Description
Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are
vulnerable to a buffer overflow condition. By specifying an excessively
long filename in a file upload request, an unauthenticated attacker can
trigger a crash of the server, resulting in a denial of service.
Depending on the stack state or if a stack canary can be disclosed
through another vulnerability, this buffer overflow could potentially be
exploited for remote code execution, leading to full compromise of the
server. This issue affects TeamDavid before Rollout 528.

Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
Published: 2026-08-07
Score: 9.5 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Possible Denial of Service or Remote Code Execution via file upload
Action: Patch Immediately
AI Analysis

Impact

The flaw is a classic buffer overflow in the handling of file names during uploads. An attacker can craft an overlong name to crash the server, causing denial of service. If a stack canary leak or an additional vulnerability is present, the overflow could be exploited for remote code execution, giving the attacker full control over the server. This issue applies to TeamDavid prior to Rollout 528, after which the vulnerable functionality is disabled by default.

Affected Systems

The Tobit Laboratories AG TeamDavid Webbox application is the affected product. Versions before Rollout 528 are vulnerable, and any environment that hosts TeamDavid and exposes the upload endpoints is susceptible.

Risk and Exploitability

The CVSS score of 9.5 indicates high severity. The vulnerability is accessible to unauthenticated attackers via normal web traffic. Although the EPSS score is very low, the flaw is not yet listed in CISA KEV. The buffer overflow occurs in a public‑facing file upload service, making the attack vector likely network based. However, starting with Rollout 528 the vulnerable functionality is disabled by default, limiting exposure to older deployments.

Generated by OpenCVE AI on September 7, 2026 at 15:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest TeamDavid release that resolves the file‑name buffer overflow.
  • If an update cannot be applied immediately, disable or restrict the upload functionality for unauthenticated users until the fix is available.
  • Enforce strict size limits on incoming file names and implement additional boundary checks in the web application firewall to prevent requests that exceed acceptable thresholds.
  • Monitor logs for anomalous upload attempts and configure alerts for repeated upload failures or crashes.

Generated by OpenCVE AI on September 7, 2026 at 15:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
References

Mon, 07 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are vulnerable to a buffer overflow condition. By specifying an excessively long filename in a file upload request, an unauthenticated attacker can trigger a crash of the server, resulting in a denial of service. Depending on the stack state or if a stack canary can be disclosed through another vulnerability, this buffer overflow could potentially be exploited for remote code execution, leading to full compromise of the server. This issue affects TeamDavid through Rollout 524. Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are vulnerable to a buffer overflow condition. By specifying an excessively long filename in a file upload request, an unauthenticated attacker can trigger a crash of the server, resulting in a denial of service. Depending on the stack state or if a stack canary can be disclosed through another vulnerability, this buffer overflow could potentially be exploited for remote code execution, leading to full compromise of the server. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
References

Fri, 07 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid
Vendors & Products Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid

Fri, 07 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are vulnerable to a buffer overflow condition. By specifying an excessively long filename in a file upload request, an unauthenticated attacker can trigger a crash of the server, resulting in a denial of service. Depending on the stack state or if a stack canary can be disclosed through another vulnerability, this buffer overflow could potentially be exploited for remote code execution, leading to full compromise of the server. This issue affects TeamDavid through Rollout 524.
Title TeamDavid: Buffer Overflow in file names of file upload functionalities
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Tobit Laboratories Ag Teamdavid
cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-09-07T12:56:54.726Z

Reserved: 2026-06-12T09:32:46.514Z

Link: CVE-2026-54210

cve-icon Vulnrichment

Updated: 2026-08-07T14:40:49.113Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T10:16:58.030

Modified: 2026-09-07T13:20:29.203

Link: CVE-2026-54210

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T16:00:13Z

Weaknesses