CVE-2026-54203
Received Received - Intake

Memory Leak in Tobit Laboratories TeamDavid Webbox

Vulnerability report for CVE-2026-54203, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: Switzerland Government Common Vulnerability Program

Description

Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessing the URL β€œ/.well-known/mta-sts.”, the application responds with memory. By repeatedly requesting this endpoint, an attacker can access sensitive information,Β including user passwords. Exploitation does not require authentication.Β This issue affects TeamDavid through Rollout 524.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tobit_laboratories_ag teamdavid to 524 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a memory leak in Tobit Laboratories AG TeamDavid's Webbox software. When an attacker repeatedly requests the URL '/.well-known/mta-sts.', the application exposes sensitive information stored in memory, including user passwords. Exploitation does not require authentication.

Detection Guidance

To detect this vulnerability, monitor repeated requests to the endpoint /.well-known/mta-sts. Check for unusual memory dumps or unauthorized access to sensitive data. Use network traffic analysis tools like Wireshark or tcpdump to inspect HTTP requests targeting this path.

Impact Analysis

An attacker could gain access to sensitive information such as user passwords by repeatedly exploiting this memory leak. This could lead to unauthorized account access, data breaches, or further compromise of the system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating privacy regulations like GDPR and HIPAA. Organizations may face legal penalties, reputational damage, and loss of trust due to non-compliance with data protection requirements.

Mitigation Strategies

Immediately restrict access to the /.well-known/mta-sts endpoint. Update TeamDavid to the latest Rollout version beyond 524. Implement rate limiting on the server to prevent excessive requests. Review logs for signs of exploitation and rotate all exposed credentials.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54203. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart