CVE-2026-54209
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-125
Lectura fuera de límites
Fecha de publicación:
07/08/2026
Última modificación:
07/08/2026
Descripción
*** Pendiente de traducción *** Tobit Laboratories AG TeamDavid&#39;s Webbox application handles password changes using a function triggered by <br />
including the string "(editini)" in the file path, writing the new <br />
password to the specified "Archive.ini" file. However, the application <br />
does not verify that the provided path actually refers to an <br />
"Archive.ini" file. If an attacker specifies a different file with <br />
excessive size, a buffer overflow occurs. This vulnerability allows an <br />
unauthenticated attacker to crash the server, resulting in denial of <br />
service. This issue affects TeamDavid through Rollout 524.
Impacto
Puntuación base 4.0
8.90
Gravedad 4.0
ALTA



