Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-54209— TeamDavid: Buffer Overflow in 'editini' function

Quick assessment

Affected
Tobit Laboratories AG TeamDavid
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Tobit Laboratories TeamDavid WebBox是Tobit Laboratories公司的一个提供邮件、消息及存档数据远程访问功能的独立Web服务器模块。 Tobit Laboratories TeamDavid WebBox Rollout 524及之前版本存在缓冲区错误漏洞,该漏洞源于通过包含“(editini)”字符串的文件路径处理密码更改,将新密码写入“Archive.ini”文件,但未验证路径是否确实指向该文件,若指定其他超大文件则发生缓冲区溢出,可能导致未经身份验证的攻

CVSS 8.9 · High EPSS 0.41% · P33

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 1

VendorProduct Version RangeStatus
Tobit Laboratories AG TeamDavid < Rollout 528 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54209

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
TeamDavid: Buffer Overflow in 'editini' function
Source: CVE Program / CVE List V5
Vulnerability Description
Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including the string "(editini)" in the file path, writing the new password to the specified "Archive.ini" file. However, the application does not verify that the provided path actually refers to an "Archive.ini" file. If an attacker specifies a different file with excessive size, a buffer overflow occurs. This vulnerability allows an unauthenticated attacker to crash the server, resulting in denial of service. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5
Vulnerability Title
Tobit Laboratories TeamDavid WebBox 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Tobit Laboratories TeamDavid WebBox是Tobit Laboratories公司的一个提供邮件、消息及存档数据远程访问功能的独立Web服务器模块。 Tobit Laboratories TeamDavid WebBox Rollout 524及之前版本存在缓冲区错误漏洞,该漏洞源于通过包含“(editini)”字符串的文件路径处理密码更改,将新密码写入“Archive.ini”文件,但未验证路径是否确实指向该文件,若指定其他超大文件则发生缓冲区溢出,可能导致未经身份验证的攻
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Tobit Laboratories AG TeamDavid 0 ~ Rollout 528 -

II. Public POCs for CVE-2026-54209

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54209

请登录查看更多情报信息。

Vendor Pages for CVE-2026-54209 (1)

Other References for CVE-2026-54209 (1)

Same Patch Batch · Tobit Laboratories AG · 2026-08-07 · 22 CVEs total

CVE-2026-54210 9.5 CRITICAL TeamDavid: Buffer Overflow in file names of file upload functionalities
CVE-2026-54212 9.5 CRITICAL TeamDavid: Buffer Overflow in JSON-parsing
CVE-2026-54211 9.5 CRITICAL TeamDavid: Buffer Overflow in multiple form data parameters
CVE-2026-54213 9.2 CRITICAL TeamDavid: Denial of Service via endpoint 'internalRestart'
CVE-2026-54203 9.2 CRITICAL TeamDavid: Memory Leak leaking sensitive information
CVE-2026-54218 8.8 HIGH TeamDavid: Weak Cryptography and Insecure Password Storage
CVE-2026-54202 8.5 HIGH TeamDavid: Path Traversal in the archive creation functionality
CVE-2026-54208 8.5 HIGH TeamDavid: Arbitrary File Write leading to Stored XSS
CVE-2026-12070 8.4 HIGH TeamDavid: Arbitrary File Deletion via form field 'scjob'
CVE-2026-54200 8.4 HIGH TeamDavid: Local File Inclusion via the form field 'scjob'
CVE-2026-54204 7.7 HIGH TeamDavid: Server-Side Request Forgery (SSRF) via 'pathnameroot' parameter in search funct
CVE-2026-54201 6.9 MEDIUM TeamDavid: Missing Authorization
CVE-2026-54207 6.3 MEDIUM TeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in move archive fun
CVE-2026-54206 6.3 MEDIUM TeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in sending function
CVE-2026-54205 6.3 MEDIUM TeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in link storing fun
CVE-2026-54215 5.3 MEDIUM TeamDavid: Open Redirect via the 'replyUrl' parameter
CVE-2026-54199 5.3 MEDIUM TeamDavid: Header Injection through request body in link storing functionality
CVE-2026-54214 5.3 MEDIUM TeamDavid: Header Injection through the 'cType' URL parameter
CVE-2026-54216 5.3 MEDIUM TeamDavid: Reflected Cross Site Scripting (XSS) via the 'EntryInfo' parameter
CVE-2026-54217 5.3 MEDIUM TeamDavid: Stored XSS in web application

Showing top 20 of 22 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-54209

No comments yet


Leave a comment