CVE-2026-54210

Severity CVSS v4.0:
CRITICAL
Type:
CWE-787 Out-of-bounds Write
Publication date:
07/08/2026
Last modified:
07/08/2026

Description

Tobit Laboratories AG TeamDavid&amp;#39;s Webbox application implements various file upload functionalities that are <br /> vulnerable to a buffer overflow condition. By specifying an excessively <br /> long filename in a file upload request, an unauthenticated attacker can <br /> trigger a crash of the server, resulting in a denial of service. <br /> Depending on the stack state or if a stack canary can be disclosed <br /> through another vulnerability, this buffer overflow could potentially be<br /> exploited for remote code execution, leading to full compromise of the <br /> server. This issue affects TeamDavid through Rollout 524.