Description
Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by
including the string "(editini)" in the file path, writing the new
password to the specified "Archive.ini" file. However, the application
does not verify that the provided path actually refers to an
"Archive.ini" file. If an attacker specifies a different file with
excessive size, a buffer overflow occurs. This vulnerability allows an
unauthenticated attacker to crash the server, resulting in denial of
service. This issue affects TeamDavid before Rollout 528.

Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
Published: 2026-08-07
Score: 8.9 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Denial of Service
Action: Patch
AI Analysis

Impact

Tobit Laboratories AG's TeamDavid Webbox application handles password changes through a function triggered by including the string "(editini)" in the file path. The function writes the new password to a specified Archive.ini file but does not verify that the given path refers to an Archive.ini file. An attacker can supply a file path with excessive size, causing a buffer overflow that crashes the server. This allows an unauthenticated attacker to cause a denial of service. The issue affects TeamDavid versions before Rollout 528; starting with Rollout 528 the affected functionality is disabled by default, eliminating exposure through this path.

Affected Systems

TeamDavid Webbox from Tobit Laboratories AG, versions before Rollout 528 are affected.

Risk and Exploitability

The CVSS score of 8.9 indicates high severity. EPSS is <1%, and the vulnerability is not listed in CISA KEV, suggesting no widespread exploitation yet. The vulnerability permits an unauthenticated attacker to trigger a buffer overflow via the password change endpoint, crashing the server and denying service. The issue is no longer exposed in versions Rollout 528 and later, so only deployments using older releases are at risk.

Generated by OpenCVE AI on September 7, 2026 at 15:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and apply the latest patch or upgrade to a TeamDavid version newer than Rollout 528 that addresses the buffer overflow.
  • Implement strict validation on the file path used for password changes so that only paths pointing to Archive.ini are accepted, and enforce bounds checking before writing to the file.
  • If a patch is not yet available, restrict unauthenticated access to the password change endpoint through network segmentation or firewall rules to block potential exploitation.

Generated by OpenCVE AI on September 7, 2026 at 15:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
References

Mon, 07 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including the string "(editini)" in the file path, writing the new password to the specified "Archive.ini" file. However, the application does not verify that the provided path actually refers to an "Archive.ini" file. If an attacker specifies a different file with excessive size, a buffer overflow occurs. This vulnerability allows an unauthenticated attacker to crash the server, resulting in denial of service. This issue affects TeamDavid through Rollout 524. Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including the string "(editini)" in the file path, writing the new password to the specified "Archive.ini" file. However, the application does not verify that the provided path actually refers to an "Archive.ini" file. If an attacker specifies a different file with excessive size, a buffer overflow occurs. This vulnerability allows an unauthenticated attacker to crash the server, resulting in denial of service. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
References

Fri, 07 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid
Vendors & Products Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid

Fri, 07 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including the string "(editini)" in the file path, writing the new password to the specified "Archive.ini" file. However, the application does not verify that the provided path actually refers to an "Archive.ini" file. If an attacker specifies a different file with excessive size, a buffer overflow occurs. This vulnerability allows an unauthenticated attacker to crash the server, resulting in denial of service. This issue affects TeamDavid through Rollout 524.
Title TeamDavid: Buffer Overflow in 'editini' function
Weaknesses CWE-125
References
Metrics cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


Subscriptions

Tobit Laboratories Ag Teamdavid
cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-09-07T12:55:59.027Z

Reserved: 2026-06-12T09:32:46.514Z

Link: CVE-2026-54209

cve-icon Vulnrichment

Updated: 2026-08-07T14:41:09.992Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T10:16:57.887

Modified: 2026-09-07T13:20:28.760

Link: CVE-2026-54209

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T15:15:17Z

Weaknesses