Description
Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a
buffer overflow condition. By submitting a specially crafted JSON body,
such as one that is at least 8 characters long and begins with a number,
an unauthenticated attacker can cause the server to crash, resulting in
denial of service. Depending on the stack state or if a stack canary
can be disclosed through another vulnerability, this buffer overflow
could potentially lead to remote code execution and full compromise of
the server. This issue affects TeamDavid before Rollout 528.

Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
Published: 2026-08-07
Score: 9.5 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service and potential Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a stack-based buffer overflow in the JSON parsing component of TeamDavid’s Webbox API (CWE‑787). An attacker can send a JSON body that is at least 8 characters long and begins with a numeric value, causing a crash and denial of service. If a related vulnerability leaks the stack canary, the overflow could be leveraged to execute arbitrary code and fully compromise the server. This issue affects TeamDavid before Rollout 528.

Affected Systems

The affected product is Tobit Laboratories AG’s TeamDavid Webbox application, affecting releases up through Rollout 528. All versions preceding that fix remain vulnerable. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerability is no longer exposed via this endpoint. The application exposes an API endpoint that processes JSON requests.

Risk and Exploitability

Based on the description, it is inferred that an unauthenticated attacker can exploit the API endpoint over the network by sending a specially crafted JSON payload. The high CVSS score of 9.5 indicates critical severity while the EPSS score is <1% indicating a low probability of exploitation, and the vulnerability is not currently listed in CISA KEV. If the attacker also exploits a separate flaw that reveals the stack canary, the buffer overflow could be used to execute arbitrary code and fully compromise the server.

Generated by OpenCVE AI on September 7, 2026 at 15:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest TeamDavid release that contains the patch for the buffer overflow in the JSON parsing API.
  • Restrict access to the vulnerable API endpoint to authenticated users or internal networks only, using firewalls or application‑level access controls.
  • Deploy application layer defenses such as a Web Application Firewall or input size limits to block malformed JSON payloads before they reach the application.

Generated by OpenCVE AI on September 7, 2026 at 15:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
References

Mon, 07 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow condition. By submitting a specially crafted JSON body, such as one that is at least 8 characters long and begins with a number, an unauthenticated attacker can cause the server to crash, resulting in denial of service. Depending on the stack state or if a stack canary can be disclosed through another vulnerability, this buffer overflow could potentially lead to remote code execution and full compromise of the server. This issue affects TeamDavid through Rollout 524. Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow condition. By submitting a specially crafted JSON body, such as one that is at least 8 characters long and begins with a number, an unauthenticated attacker can cause the server to crash, resulting in denial of service. Depending on the stack state or if a stack canary can be disclosed through another vulnerability, this buffer overflow could potentially lead to remote code execution and full compromise of the server. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
References

Sat, 08 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid
Vendors & Products Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid

Fri, 07 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow condition. By submitting a specially crafted JSON body, such as one that is at least 8 characters long and begins with a number, an unauthenticated attacker can cause the server to crash, resulting in denial of service. Depending on the stack state or if a stack canary can be disclosed through another vulnerability, this buffer overflow could potentially lead to remote code execution and full compromise of the server. This issue affects TeamDavid through Rollout 524.
Title TeamDavid: Buffer Overflow in JSON-parsing
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Tobit Laboratories Ag Teamdavid
cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-09-07T12:58:58.837Z

Reserved: 2026-06-12T09:32:46.514Z

Link: CVE-2026-54212

cve-icon Vulnrichment

Updated: 2026-08-07T14:38:17.228Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T10:16:58.353

Modified: 2026-09-07T13:20:30.067

Link: CVE-2026-54212

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T16:00:13Z

Weaknesses