CVE-2026-54218: TeamDavid: Weak Cryptography and Insecure Password Storage
Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally in David, passwords are stored in various files using only obfuscation. Any user with access to the server’s file system, or who can otherwise extract files from the server (see vulnerability “Random File Read”), can potentially obtain affected users’ passwords. This issue affects TeamDavid through Rollout 524.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-54218?
CVE-2026-54218 has a risk score of 44, indicating a potential security threat associated with weak cryptography and insecure password storage.
What are the main issues of CVE-2026-54218?
CVE-2026-54218 is primarily concerned with the use of hard-coded cryptographic keys and the obfuscation of passwords stored in files.
Who is affected by CVE-2026-54218?
Users of Tobit Laboratories AG TeamDavid's Webbox who create accounts locally are potentially affected by CVE-2026-54218.
How do I fix CVE-2026-54218?
To address CVE-2026-54218, it is crucial to avoid hard-coded cryptographic keys and implement secure password storage practices.
What are the potential risks of CVE-2026-54218?
The risks associated with CVE-2026-54218 include unauthorized access to sensitive information due to weak cryptography and insecure password handling.