Impact
Tobit Laboratories AG's TeamDavid Webbox application processes password changes through a function triggered by including the string "(editini)" in a file path. The function writes the new password to an Archive.ini file but does not verify that the provided path actually refers to an Archive.ini file. An attacker can supply a different file path with an excessively large value, causing a buffer overflow that crashes the server. This vulnerability permits an unauthenticated attacker to result in denial of service and is identified as CWE‑125: Out‑of‑Bounds Read.
Affected Systems
TeamDavid Webbox from Tobit Laboratories AG, versions through Rollout 524 are affected.
Risk and Exploitability
The CVSS score of 8.9 indicates high severity. EPSS is not available, and the vulnerability is not listed in CISA KEV, suggesting no widespread exploitation yet. The likely attack vector is remote unauthenticated path manipulation via the password change endpoint, which an attacker can use to trigger the overflow and disrupt service availability.
OpenCVE Enrichment