Impact
Tobit Laboratories AG’s TeamDavid Webbox lacks authentication when serving log files, allowing any user to retrieve detailed error messages and internal data. The exposed information can assist an attacker in mapping the application or identifying further weaknesses, potentially increasing the overall attack surface. The weakness is a classic example of missing authorization (CWE‑862).
Affected Systems
The vulnerability affects the TeamDavid Webbox component of Tobit Laboratories AG, specifically versions served up through Rollout 524. All deployments of this roll‑out that expose the default log‑file endpoints are impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the EPSS score is not available, but the issue is not listed in CISA KEV. Attackers can exploit the flaw remotely by simply accessing the exposed URLs without authentication, making the threat relatively low‑cost but potentially valuable for reconnaissance. Due to the lack of preventative checks, the exploitability is high for any system exposing the default log‑file routes over the network.
OpenCVE Enrichment