Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-54210

Gravedad CVSS v4.0:
CRÍTICA
Tipo:
CWE-787 Escritura fuera de límites
Fecha de publicación:
07/08/2026
Última modificación:
07/08/2026

Descripción

*** Pendiente de traducción *** Tobit Laboratories AG TeamDavid&amp;#39;s Webbox application implements various file upload functionalities that are <br /> vulnerable to a buffer overflow condition. By specifying an excessively <br /> long filename in a file upload request, an unauthenticated attacker can <br /> trigger a crash of the server, resulting in a denial of service. <br /> Depending on the stack state or if a stack canary can be disclosed <br /> through another vulnerability, this buffer overflow could potentially be<br /> exploited for remote code execution, leading to full compromise of the <br /> server. This issue affects TeamDavid through Rollout 524.