PT-2026-68914 · Tobit Laboratories Ag · Teamdavid
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
TeamDavid versions prior to Rollout 525
Description
Tobit Laboratories AG TeamDavid's Webbox contains a flaw where a hard-coded cryptographic key is used. Passwords for users created locally in David are stored in multiple files using only obfuscation, which is a method of making data difficult for humans to read but does not provide strong security. An attacker with access to the server file system or the ability to extract files from the server can potentially retrieve these passwords.
Recommendations
Update TeamDavid to a version later than Rollout 524.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Teamdavid