CVE-2026-54209

Severity CVSS v4.0:
HIGH
Type:
CWE-125 Out-of-bounds Read
Publication date:
07/08/2026
Last modified:
07/08/2026

Description

Tobit Laboratories AG TeamDavid&amp;#39;s Webbox application handles password changes using a function triggered by <br /> including the string "(editini)" in the file path, writing the new <br /> password to the specified "Archive.ini" file. However, the application <br /> does not verify that the provided path actually refers to an <br /> "Archive.ini" file. If an attacker specifies a different file with <br /> excessive size, a buffer overflow occurs. This vulnerability allows an <br /> unauthenticated attacker to crash the server, resulting in denial of <br /> service. This issue affects TeamDavid through Rollout 524.