Impact
Tobit Laboratories AG’s TeamDavid Webbox lacks authentication or authorization checks when serving log files, allowing any user to retrieve detailed error messages and internal data. The exposed information can aid an attacker in mapping the application or identifying additional weaknesses, potentially facilitating further attacks.
Affected Systems
The vulnerability affects the TeamDavid Webbox component of Tobit Laboratories AG, specifically versions released before Rollout 528. All deployments that expose the default log‑file endpoints in those versions are impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the EPSS score is 0.00324 (approximately 0.3%), showing very low but nonzero exploitation probability. The issue is not listed in CISA KEV. Attackers can exploit the flaw remotely by simply accessing the exposed URLs without authentication, making the threat relatively low‑cost but potentially valuable for reconnaissance. This attack is only possible on versions before Rollout 528, since the functionality is disabled by default thereafter. Due to the lack of preventative checks, the exploitability is high for any system exposing the default log‑file routes over the network.
OpenCVE Enrichment