High severityNVD Advisory· Published Aug 7, 2026· Updated Sep 7, 2026
CVE-2026-54218
CVE-2026-54218
Description
Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally in David, passwords are stored in various files using only obfuscation. Any user with access to the server’s file system, or who can otherwise extract files from the server (see vulnerability “Random File Read”), can potentially obtain affected users’ passwords. This issue affects TeamDavid before Rollout 528.
Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <Rollout 528
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.