Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-54204— TeamDavid: Server-Side Request Forgery (SSRF) via 'pathnameroot' parameter in search functionality

CVSS 7.7 · High EPSS 0.33% · P25

Affected Version Matrix 1

VendorProductVersion RangeStatus
Tobit Laboratories AGTeamDavid≤ Rollout 524affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-54204

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
TeamDavid: Server-Side Request Forgery (SSRF) via 'pathnameroot' parameter in search functionality
Source: CVE Program / CVE List V5
Vulnerability Description
Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The server processes these paths without validation, resulting in outbound connection attempts to attacker-controlled SMB servers. This enables unauthenticated attackers to trigger the server to authenticate to arbitrary SMB endpoints, potentially exposing NTLM authentication information (such as NTLM hashes). If outbound connections to port 445 (SMB) are permitted, attackers can use this to conduct SMB relay or credential theft attacks. Exploitation of the “pathnameroot” parameter is possible without authentication. This issue affects TeamDavid through Rollout 524.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
Tobit Laboratories AGTeamDavid 0 ~ Rollout 524 -

II. Public POCs for CVE-2026-54204

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54204

登录查看更多情报信息。

Vendor Pages for CVE-2026-54204 (1)

Same Patch Batch · Tobit Laboratories AG · 2026-08-07 · 22 CVEs total

CVE-2026-542109.5 CRITICALTeamDavid: Buffer Overflow in file names of file upload functionalities
CVE-2026-542119.5 CRITICALTeamDavid: Buffer Overflow in multiple form data parameters
CVE-2026-542129.5 CRITICALTeamDavid: Buffer Overflow in JSON-parsing
CVE-2026-542139.2 CRITICALTeamDavid: Denial of Service via endpoint 'internalRestart'
CVE-2026-542039.2 CRITICALTeamDavid: Memory Leak leaking sensitive information
CVE-2026-542098.9 HIGHTeamDavid: Buffer Overflow in 'editini' function
CVE-2026-542188.8 HIGHTeamDavid: Weak Cryptography and Insecure Password Storage
CVE-2026-542028.5 HIGHTeamDavid: Path Traversal in the archive creation functionality
CVE-2026-542088.5 HIGHTeamDavid: Arbitrary File Write leading to Stored XSS
CVE-2026-120708.4 HIGHTeamDavid: Arbitrary File Deletion via form field 'scjob'
CVE-2026-542008.4 HIGHTeamDavid: Local File Inclusion via the form field 'scjob'
CVE-2026-542016.9 MEDIUMTeamDavid: Missing Authorization
CVE-2026-542056.3 MEDIUMTeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in link storing fun
CVE-2026-542066.3 MEDIUMTeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in sending function
CVE-2026-542076.3 MEDIUMTeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in move archive fun
CVE-2026-542155.3 MEDIUMTeamDavid: Open Redirect via the 'replyUrl' parameter
CVE-2026-541995.3 MEDIUMTeamDavid: Header Injection through request body in link storing functionality
CVE-2026-542145.3 MEDIUMTeamDavid: Header Injection through the 'cType' URL parameter
CVE-2026-542165.3 MEDIUMTeamDavid: Reflected Cross Site Scripting (XSS) via the 'EntryInfo' parameter
CVE-2026-542175.3 MEDIUMTeamDavid: Stored XSS in web application

Showing top 20 of 22 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-54204

No comments yet


Leave a comment