{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-54211", "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c", "state": "PUBLISHED", "assignerShortName": "NCSC.ch", "dateReserved": "2026-06-12T09:32:46.514Z", "datePublished": "2026-08-07T09:46:50.005Z", "dateUpdated": "2026-09-07T12:58:13.534Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "455daabc-a392-441d-aa46-37d35189897c", "shortName": "NCSC.ch", "dateUpdated": "2026-09-07T12:58:13.534Z" }, "title": "TeamDavid: Buffer Overflow in multiple form data parameters", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-787", "description": "CWE-787 Out-of-bounds write", "type": "CWE" } ] } ], "affected": [ { "vendor": "Tobit Laboratories AG", "product": "TeamDavid", "modules": [ "Webbox" ], "versions": [ { "status": "affected", "version": "0", "lessThan": "Rollout 528", "versionType": "custom" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a\n buffer overflow vulnerability in multiple form data parameters. By \nsubmitting excessively long values in these parameters, an authenticated\n attacker can trigger a server crash, resulting in denial of service. \nDepending on the stack state or if a stack canary can be disclosed \nthrough another vulnerability, this buffer overflow could potentially be\n exploited for remote code execution, leading to full compromise of the \nserver. This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a\n buffer overflow vulnerability in multiple form data parameters. By \nsubmitting excessively long values in these parameters, an authenticated\n attacker can trigger a server crash, resulting in denial of service. \nDepending on the stack state or if a stack canary can be disclosed \nthrough another vulnerability, this buffer overflow could potentially be\n exploited for remote code execution, leading to full compromise of the \nserver.