CVE-2026-54218: CWE-321 Use of hard-coded cryptographic key in Tobit Laboratories AG TeamDavid
CVE-2026-54218 is a vulnerability in Tobit Laboratories AG TeamDavid's Webbox where a hard-coded cryptographic key is used. This results in locally created user passwords being stored with only obfuscation in various files. An attacker with access to the server's file system or the ability to extract files can potentially retrieve these passwords. The issue affects versions before Rollout 528. Starting with Rollout 528 (June 30, 2026), the vulnerable functionality is disabled by default, mitigating exposure.
AI Analysis
Technical Summary
This vulnerability involves the use of a hard-coded cryptographic key in TeamDavid's Webbox, leading to weak protection of locally created user passwords stored in files with only obfuscation. Any user or attacker with file system access or the ability to extract files from the server can potentially obtain these passwords. The vulnerability affects TeamDavid versions prior to Rollout 528. From Rollout 528 onward, the affected functionality is disabled by default, reducing the risk of exploitation.
Potential Impact
The vulnerability allows unauthorized parties with access to the server's file system or file extraction capabilities to obtain user passwords that are insufficiently protected due to the use of a hard-coded cryptographic key and weak obfuscation. This compromises user credential confidentiality and could lead to unauthorized access to user accounts.
Mitigation Recommendations
Upgrade to TeamDavid Rollout 528 or later, where the vulnerable functionality is disabled by default, effectively mitigating the exposure. Since the vulnerability is addressed by disabling the affected functionality starting with Rollout 528, users should apply this update to remediate the issue.
CVE-2026-54218: CWE-321 Use of hard-coded cryptographic key in Tobit Laboratories AG TeamDavid
Description
CVE-2026-54218 is a vulnerability in Tobit Laboratories AG TeamDavid's Webbox where a hard-coded cryptographic key is used. This results in locally created user passwords being stored with only obfuscation in various files. An attacker with access to the server's file system or the ability to extract files can potentially retrieve these passwords. The issue affects versions before Rollout 528. Starting with Rollout 528 (June 30, 2026), the vulnerable functionality is disabled by default, mitigating exposure.
CVSS v4.0
Score 8.8high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves the use of a hard-coded cryptographic key in TeamDavid's Webbox, leading to weak protection of locally created user passwords stored in files with only obfuscation. Any user or attacker with file system access or the ability to extract files from the server can potentially obtain these passwords. The vulnerability affects TeamDavid versions prior to Rollout 528. From Rollout 528 onward, the affected functionality is disabled by default, reducing the risk of exploitation.
Potential Impact
The vulnerability allows unauthorized parties with access to the server's file system or file extraction capabilities to obtain user passwords that are insufficiently protected due to the use of a hard-coded cryptographic key and weak obfuscation. This compromises user credential confidentiality and could lead to unauthorized access to user accounts.
Mitigation Recommendations
Upgrade to TeamDavid Rollout 528 or later, where the vulnerable functionality is disabled by default, effectively mitigating the exposure. Since the vulnerability is addressed by disabling the affected functionality starting with Rollout 528, users should apply this update to remediate the issue.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-96qv-r2x5-ffch
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-54218"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a75f70dbf8831d53984f63a
Added to database: 08/07/2026, 15:17:33 UTC
Last enriched: 09/07/2026, 17:05:08 UTC
Last updated: 09/22/2026, 13:47:46 UTC
Views: 42
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.