CVE-2026-54209
Severity CVSS v4.0:
HIGH
Type:
CWE-125
Out-of-bounds Read
Publication date:
07/08/2026
Last modified:
07/08/2026
Description
Tobit Laboratories AG TeamDavid&#39;s Webbox application handles password changes using a function triggered by <br />
including the string "(editini)" in the file path, writing the new <br />
password to the specified "Archive.ini" file. However, the application <br />
does not verify that the provided path actually refers to an <br />
"Archive.ini" file. If an attacker specifies a different file with <br />
excessive size, a buffer overflow occurs. This vulnerability allows an <br />
unauthenticated attacker to crash the server, resulting in denial of <br />
service. This issue affects TeamDavid through Rollout 524.
Impact
Base Score 4.0
8.90
Severity 4.0
HIGH



