Description
Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessing the URL “/.well-known/mta-sts.”, the application responds
with memory. By repeatedly
requesting this endpoint, an attacker can access sensitive
information, including user passwords. Exploitation does not require
authentication. This issue affects TeamDavid through Rollout 524.
Published: 2026-08-07
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A memory leak flaw in Tobit Laboratories AG’s TeamDavid Webbox lets any network user retrieve private data from the server without authentication. By repeatedly requesting the endpoint "/.well-known/mta-sts.", the application returns bytes from memory that may contain user passwords and other confidential information. This flaw allows an attacker to exfiltrate credentials and other sensitive data, potentially leading to account compromise and broader system infiltration.

Affected Systems

The vulnerability affects the TeamDavid Webbox version managed through Rollout 524. No other versions are listed as affected in the current advisory.

Risk and Exploitability

The CVSS score of 9.2 marks the issue as critical. Because authentication is not required, an attacker can exploit the flaw from any system that can reach the vulnerable URL, making remote exploitation straightforward. The EPSS score is not available, but the high CVSS suggests a strong likelihood of exploitation. The vulnerability is not yet in the CISA KEV list, but the impact warrants immediate attention.

Generated by OpenCVE AI on August 7, 2026 at 11:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest TeamDavid release that contains the memory‑leak fix.
  • Configure the web server or application firewall to block or require authentication for the "/.well-known/mta-sts." endpoint.
  • Implement rate limiting to prevent repeated read requests from any single source.
  • Conduct regular vulnerability scans targeting the endpoint and monitor logs for anomalous access patterns.

Generated by OpenCVE AI on August 7, 2026 at 11:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 08 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid
Vendors & Products Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid

Fri, 07 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessing the URL “/.well-known/mta-sts.”, the application responds with memory. By repeatedly requesting this endpoint, an attacker can access sensitive information, including user passwords. Exploitation does not require authentication. This issue affects TeamDavid through Rollout 524.
Title TeamDavid: Memory Leak leaking sensitive information
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

Tobit Laboratories Ag Teamdavid
cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-08-10T11:42:11.221Z

Reserved: 2026-06-12T09:32:44.531Z

Link: CVE-2026-54203

cve-icon Vulnrichment

Updated: 2026-08-10T11:42:06.673Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T10:16:57.070

Modified: 2026-08-26T16:39:25.163

Link: CVE-2026-54203

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T20:41:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor