Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-54212

Gravedad CVSS v4.0:
CRÍTICA
Tipo:
CWE-787 Escritura fuera de límites
Fecha de publicación:
07/08/2026
Última modificación:
07/08/2026

Descripción

*** Pendiente de traducción *** Tobit Laboratories AG TeamDavid&amp;#39;s Webbox application implements an API endpoint that is vulnerable to a <br /> buffer overflow condition. By submitting a specially crafted JSON body, <br /> such as one that is at least 8 characters long and begins with a number,<br /> an unauthenticated attacker can cause the server to crash, resulting in<br /> denial of service. Depending on the stack state or if a stack canary <br /> can be disclosed through another vulnerability, this buffer overflow <br /> could potentially lead to remote code execution and full compromise of <br /> the server. This issue affects TeamDavid through Rollout 524.