Description
Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a
buffer overflow vulnerability in multiple form data parameters. By
submitting excessively long values in these parameters, an authenticated
attacker can trigger a server crash, resulting in denial of service.
Depending on the stack state or if a stack canary can be disclosed
through another vulnerability, this buffer overflow could potentially be
exploited for remote code execution, leading to full compromise of the
server. This issue affects TeamDavid before Rollout 528.

Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
Published: 2026-08-07
Score: 9.5 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service; potential Remote Code Execution
Action: Immediate patch
AI Analysis

Impact

The vulnerability is a classic stack buffer overflow present in the Webbox application’s endpoint //serverClient_close.html. An authenticated attacker can supply excessively large values in form data parameters, causing the server to crash and leading to denial of service. If, in addition, a stack canary can be disclosed via another vulnerability or the stack state is manipulated, this overflow could be leveraged to execute arbitrary code on the server, potentially resulting in full compromise.

Affected Systems

This flaw affects the TeamDavid Webbox application from Tobit Laboratories AG before Rollout 528. The vulnerability resides in the endpoint that handles server shutdown requests, which is accessible only to authenticated users with the appropriate permissions. In Rollout 528 and later the affected functionality is disabled by default, so the vulnerability is no longer exposed.

Risk and Exploitability

The CVSS score of 9.5 indicates a critical severity. The EPSS score of 0.0041 indicates a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The attack requires authenticated access and the ability to submit long form data, making exploitation likely easier in environments where users create accounts or where credential exposure is possible. Without a stack canary leak, the primary impact is a denial of service. If a stack canary can be bypassed, remote code execution could be achieved, which would be catastrophic for the affected servers.

Generated by OpenCVE AI on September 7, 2026 at 15:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest release of TeamDavid that contains the buffer overflow fix and upgrade to Rollout 528 or later.
  • Restrict or disable the //serverClient_close.html endpoint for non-essential users, limiting exposure to authenticated users only.
  • Enforce strong authentication practices and monitor account activity for suspicious data submissions, blocking clients that attempt to send unusually large payloads.

Generated by OpenCVE AI on September 7, 2026 at 15:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
References

Mon, 07 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer overflow vulnerability in multiple form data parameters. By submitting excessively long values in these parameters, an authenticated attacker can trigger a server crash, resulting in denial of service. Depending on the stack state or if a stack canary can be disclosed through another vulnerability, this buffer overflow could potentially be exploited for remote code execution, leading to full compromise of the server. This issue affects TeamDavid through Rollout 524. Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer overflow vulnerability in multiple form data parameters. By submitting excessively long values in these parameters, an authenticated attacker can trigger a server crash, resulting in denial of service. Depending on the stack state or if a stack canary can be disclosed through another vulnerability, this buffer overflow could potentially be exploited for remote code execution, leading to full compromise of the server. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
References

Fri, 07 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid
Vendors & Products Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid

Fri, 07 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer overflow vulnerability in multiple form data parameters. By submitting excessively long values in these parameters, an authenticated attacker can trigger a server crash, resulting in denial of service. Depending on the stack state or if a stack canary can be disclosed through another vulnerability, this buffer overflow could potentially be exploited for remote code execution, leading to full compromise of the server. This issue affects TeamDavid through Rollout 524.
Title TeamDavid: Buffer Overflow in multiple form data parameters
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Tobit Laboratories Ag Teamdavid
cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-09-07T12:58:13.534Z

Reserved: 2026-06-12T09:32:46.514Z

Link: CVE-2026-54211

cve-icon Vulnrichment

Updated: 2026-08-07T14:39:32.789Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T10:16:58.170

Modified: 2026-09-07T13:20:29.623

Link: CVE-2026-54211

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T16:00:13Z

Weaknesses