Tobit Laboratories AG
Tobit Laboratories AG Teamdavid: vulnerabilidades y CVE
Tobit Laboratories AG Teamdavid tiene 19 vulnerabilidades publicadas, 19 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE19
Últimos 12 meses19
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-54218 | Alta (8.8) | 0.46% | — | 7 ago 2026 | Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally in David, passwords are stored in various files using only obfuscation. Any user with access to… |
| CVE-2026-54217 | Media (5.3) | 0.44% | — | 7 ago 2026 | Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send an email containing malicious JavaScript code. When a user accesses the email, the stored cross-site… |
| CVE-2026-54216 | Media (5.3) | 0.45% | — | 7 ago 2026 | Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) vulnerability. By sending a specially crafted link including an arbitrary path, an XSS payload or the parameter… |
| CVE-2026-54215 | Media (5.3) | 0.46% | — | 7 ago 2026 | Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An attacker can exploit this vulnerability to craft a URL within the application that, when visited,… |
| CVE-2026-54214 | Media (5.3) | 0.46% | — | 7 ago 2026 | Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL parameter, which allows arbitrary modification of the Content-Type header in HTTP responses. Because… |
| CVE-2026-54213 | Crítica (9.2) | 0.71% | — | 7 ago 2026 | Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/internalRestart) is accessed. This endpoint is accessible to unauthenticated… |
| CVE-2026-54212 | Crítica (9.5) | 0.66% | — | 7 ago 2026 | Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow condition. By submitting a specially crafted JSON body, such as one that is at least 8 characters… |
| CVE-2026-54211 | Crítica (9.5) | 0.64% | — | 7 ago 2026 | Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer overflow vulnerability in multiple form data parameters. By submitting excessively long values in… |
| CVE-2026-54209 | Alta (8.9) | 0.41% | — | 7 ago 2026 | Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including the string "(editini)" in the file path, writing the new password to the specified "Archive.ini"… |
| CVE-2026-54207 | Media (6.3) | 0.49% | — | 7 ago 2026 | Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The server processes… |
| CVE-2026-54206 | Media (6.3) | 0.49% | — | 7 ago 2026 | Tobit Laboratories AG TeamDavid's Webbox 's sending email, fax, SMS, etc. functionality accepts a @@INCLUDE command, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The server processes… |
| CVE-2026-54205 | Media (6.3) | 0.49% | — | 7 ago 2026 | Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname” parameter, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The… |
| CVE-2026-54204 | Alta (7.7) | 0.57% | — | 7 ago 2026 | Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The server processes these paths… |
| CVE-2026-54203 | Crítica (9.2) | 0.56% | — | 7 ago 2026 | Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessing the URL “/.well-known/mta-sts.”, the application responds with… |
| CVE-2026-54202 | Alta (8.5) | 0.45% | — | 7 ago 2026 | Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation functionality. Because the archive path is user-controlled and insufficiently validated, an attacker can… |
| CVE-2026-54201 | Media (6.9) | 0.57% | — | 7 ago 2026 | Tobit Laboratories AG TeamDavid's Webbox does not enforce authentication or authorization checks when serving these log files. As a result, attackers can obtain sensitive error information or internal application… |
| CVE-2026-54200 | Alta (8.4) | 0.40% | — | 7 ago 2026 | Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an '@@attach' command in the form field 'scjob', files can be… |
| CVE-2026-12071 | Media (5.3) | 0.46% | — | 7 ago 2026 | The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input, which is appended to the redirect target in a 302 HTTP response. By using URL-encoded characters such as “%2e”… |
| CVE-2026-12070 | Alta (8.4) | 0.40% | — | 7 ago 2026 | Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an @@COMMENTFILE command in the form field scjob, any… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.