Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-54211

Gravedad CVSS v4.0:
CRÍTICA
Tipo:
CWE-787 Escritura fuera de límites
Fecha de publicación:
07/08/2026
Última modificación:
07/08/2026

Descripción

*** Pendiente de traducción *** Tobit Laboratories AG TeamDavid&amp;#39;s Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a<br /> buffer overflow vulnerability in multiple form data parameters. By <br /> submitting excessively long values in these parameters, an authenticated<br /> attacker can trigger a server crash, resulting in denial of service. <br /> Depending on the stack state or if a stack canary can be disclosed <br /> through another vulnerability, this buffer overflow could potentially be<br /> exploited for remote code execution, leading to full compromise of the <br /> server. This issue affects TeamDavid through Rollout 524.