PT-2026-68901 · Teamdavid · Teamdavid
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
TeamDavid versions prior to Rollout 525
Description
The link storing functionality at the endpoint '//ServerClient celink.htm' accepts a
pathname parameter that can be set to network locations using UNC paths. The server processes these paths without validation, leading to outbound connection attempts to attacker-controlled SMB servers. This allows attackers to trigger the server to authenticate to arbitrary SMB endpoints, potentially exposing NTLM authentication information, such as NTLM hashes. If outbound connections to port 445 (SMB) are permitted, this can be used for SMB relay or credential theft attacks. This issue can be exploited without authentication.Recommendations
Update to a version later than Rollout 524.
Restrict outbound connections to port 445 (SMB) to minimize the risk of credential theft.
Exploit
Fix
RCE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Teamdavid