Impact
The flaw is a classic buffer overflow in the handling of file names during uploads. An attacker can craft an overlong name to crash the server. If a stack canary leak or an additional vulnerability is present, the overflow could be leveraged for arbitrary code execution, giving the attacker full control.
Affected Systems
The Tobit Laboratories AG TeamDavid Webbox application is the affected product. Versions up to Rollout 524 are vulnerable, and any environment that hosts TeamDavid and exposes the upload endpoints is susceptible.
Risk and Exploitability
With a CVSS score of 9.5, the severity is high. No EPSS data is currently available, but the vulnerability can be triggered by unauthenticated attackers via normal web traffic. The issue is not listed in CISA KEV yet, but its nature suggests potential for exploitation. Because the overflow occurs in a public-facing upload service, the attack vector is likely network based.
OpenCVE Enrichment