PT-2026-68901 · Teamdavid · Teamdavid

·

CVE-2026-54205

·

Published

2026-08-07

·

Updated

2026-08-07

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions TeamDavid versions prior to Rollout 525
Description The link storing functionality at the endpoint '//ServerClient celink.htm' accepts a pathname parameter that can be set to network locations using UNC paths. The server processes these paths without validation, leading to outbound connection attempts to attacker-controlled SMB servers. This allows attackers to trigger the server to authenticate to arbitrary SMB endpoints, potentially exposing NTLM authentication information, such as NTLM hashes. If outbound connections to port 445 (SMB) are permitted, this can be used for SMB relay or credential theft attacks. This issue can be exploited without authentication.
Recommendations Update to a version later than Rollout 524. Restrict outbound connections to port 445 (SMB) to minimize the risk of credential theft.

Exploit

Fix

RCE

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54205

Affected Products

Teamdavid