Buffer Overflow Vulnerability in Tobit Laboratories' TeamDavid Webbox Application
CVE-2026-54209

8.9HIGH

Key Information:

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-54209?

The TeamDavid Webbox application by Tobit Laboratories contains a buffer overflow vulnerability that can be exploited through the alteration of file paths when changing passwords. An attacker can manipulate the system by appending the string '(editini)' to create arbitrary file paths, allowing for the introduction of excessively large files. This oversight results in a potential denial of service, as the application does not confirm the integrity of the specified 'Archive.ini' file, making the server susceptible to crashes. Effective mitigation requires prompt attention to this vulnerability found in the latest Rollout 524.

Affected Version(s)

TeamDavid 0

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dario Weiss of InfoGuard Labs
.