Impact
Tobit Laboratories AG TeamDavid’s Webbox is vulnerable to HTTP header injection through the request body in its link storing functionality. If an attacker supplies a line feed in the request body, that character is appended to the redirect target in the 302 HTTP response, granting control over the response headers and enabling manipulation of redirect behavior. The issue affects TeamDavid versions prior to Rollout 528; starting with Rollout 528, the affected functionality is disabled by default, eliminating the exposure in newer releases.
Affected Systems
The vulnerability affects all TeamDavid releases before Rollout 528. The affected vendor is Tobit Laboratories AG. No additional version details are provided beyond the rollout identifier.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of < 1 % suggests a low likelihood of exploitation. The issue is not listed in the CISA KEV catalog. Likely attack vectors require the ability to send crafted HTTP requests to the link storing endpoint; if that endpoint is exposed externally, the vulnerability can be triggered. For releases before Rollout 528 this remains a moderate risk, but starting with Rollout 528 the affected functionality is disabled by default, mitigating the threat.
OpenCVE Enrichment