Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.5

CVE-2026-54212: TeamDavid Webbox: Server Crash from Malicious JSON

CVE-2026-54212 · published 28 days ago
Summary

The TeamDavid Webbox application has a security issue that allows an attacker to crash the server by sending a specially crafted JSON message. This could lead to the server being unavailable, and potentially even allow an attacker to take control of the server. Users should update to a newer version of TeamDavid to fix this issue.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
tobit laboratories ag teamdavid <= Rollout 524
Original advisory text
TeamDavid: Buffer Overflow in JSON-parsing
Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a
buffer overflow condition. By submitting a specially crafted JSON body,
such as one that is at least 8 characters long and begins with a number,
an unauthenticated attacker can cause the server to crash, resulting in
denial of service. Depending on the stack state or if a stack canary
can be disclosed through another vulnerability, this buffer overflow
could potentially lead to remote code execution and full compromise of
the server. This issue affects TeamDavid through Rollout 524.
Severity
9.5 Critical
CVSS 4.0: 9.5 (NVD)
Exploitation
EPSS <1%
Type
CWE-787Out-of-bounds Write
Timeline
Published7 Aug 2026
Updated3 Sep 2026
First seen7 Aug 2026
Sources
CVE-2026-54212 · MITRE
Monitor software like this
Free during beta