CVE-2026-54210
Severity CVSS v4.0:
CRITICAL
Type:
CWE-787
Out-of-bounds Write
Publication date:
07/08/2026
Last modified:
07/08/2026
Description
Tobit Laboratories AG TeamDavid&#39;s Webbox application implements various file upload functionalities that are <br />
vulnerable to a buffer overflow condition. By specifying an excessively <br />
long filename in a file upload request, an unauthenticated attacker can <br />
trigger a crash of the server, resulting in a denial of service. <br />
Depending on the stack state or if a stack canary can be disclosed <br />
through another vulnerability, this buffer overflow could potentially be<br />
exploited for remote code execution, leading to full compromise of the <br />
server. This issue affects TeamDavid through Rollout 524.
Impact
Base Score 4.0
9.50
Severity 4.0
CRITICAL



