Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-54209

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-125 Lectura fuera de límites
Fecha de publicación:
07/08/2026
Última modificación:
07/08/2026

Descripción

*** Pendiente de traducción *** Tobit Laboratories AG TeamDavid&amp;#39;s Webbox application handles password changes using a function triggered by <br /> including the string "(editini)" in the file path, writing the new <br /> password to the specified "Archive.ini" file. However, the application <br /> does not verify that the provided path actually refers to an <br /> "Archive.ini" file. If an attacker specifies a different file with <br /> excessive size, a buffer overflow occurs. This vulnerability allows an <br /> unauthenticated attacker to crash the server, resulting in denial of <br /> service. This issue affects TeamDavid through Rollout 524.