Description
Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a
buffer overflow condition. By submitting a specially crafted JSON body,
such as one that is at least 8 characters long and begins with a number,
an unauthenticated attacker can cause the server to crash, resulting in
denial of service. Depending on the stack state or if a stack canary
can be disclosed through another vulnerability, this buffer overflow
could potentially lead to remote code execution and full compromise of
the server. This issue affects TeamDavid through Rollout 524.
Published: 2026-08-07
Score: 9.5 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack-based buffer overflow in the JSON parsing component of TeamDavid’s Webbox API. An attacker can send a JSON body that is at least 8 characters long and begins with a numeric value, causing a crash and denial of service. If a related vulnerability leaks the stack canary, the overflow could be leveraged to execute arbitrary code and fully compromise the server.

Affected Systems

The affected product is Tobit Laboratories AG’s TeamDavid Webbox application, affecting releases up through Rollout 524. All versions preceding that fix remain vulnerable. The application exposes an API endpoint that processes JSON requests.

Risk and Exploitability

Based on the description, it is inferred that an unauthenticated attacker can exploit the API endpoint over the network by sending a specially crafted JSON payload. The high CVSS score of 9.5 indicates critical severity while the EPSS score is not reported and the vulnerability is not currently listed in CISA KEV. If the attacker also exploits a separate flaw that reveals the stack canary, the buffer overflow could be used to execute arbitrary code and fully compromise the server.

Generated by OpenCVE AI on August 7, 2026 at 11:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest TeamDavid release that contains the patch for the buffer overflow in the JSON parsing API.
  • Restrict access to the vulnerable API endpoint to authenticated users or internal networks only, using firewalls or application-level access controls.
  • Deploy application layer defenses such as a Web Application Firewall or input size limits to block malformed JSON payloads before they reach the application.

Generated by OpenCVE AI on August 7, 2026 at 11:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow condition. By submitting a specially crafted JSON body, such as one that is at least 8 characters long and begins with a number, an unauthenticated attacker can cause the server to crash, resulting in denial of service. Depending on the stack state or if a stack canary can be disclosed through another vulnerability, this buffer overflow could potentially lead to remote code execution and full compromise of the server. This issue affects TeamDavid through Rollout 524.
Title TeamDavid: Buffer Overflow in JSON-parsing
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-08-07T09:47:12.542Z

Reserved: 2026-06-12T09:32:46.514Z

Link: CVE-2026-54212

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T11:30:03Z

Weaknesses