Impact
The flaw is a classic buffer overflow in the handling of file names during uploads. An attacker can craft an overlong name to crash the server, causing denial of service. If a stack canary leak or an additional vulnerability is present, the overflow could be exploited for remote code execution, giving the attacker full control over the server. This issue applies to TeamDavid prior to Rollout 528, after which the vulnerable functionality is disabled by default.
Affected Systems
The Tobit Laboratories AG TeamDavid Webbox application is the affected product. Versions before Rollout 528 are vulnerable, and any environment that hosts TeamDavid and exposes the upload endpoints is susceptible.
Risk and Exploitability
The CVSS score of 9.5 indicates high severity. The vulnerability is accessible to unauthenticated attackers via normal web traffic. Although the EPSS score is very low, the flaw is not yet listed in CISA KEV. The buffer overflow occurs in a public‑facing file upload service, making the attack vector likely network based. However, starting with Rollout 528 the vulnerable functionality is disabled by default, limiting exposure to older deployments.
OpenCVE Enrichment