Impact
A memory leak flaw in Tobit Laboratories AG’s TeamDavid Webbox allows an attacker to read sensitive information from memory without authentication. By accessing the endpoint "/.well-known/mta-sts.", the application returns memory contents; repeating requests can reveal confidential data such as user passwords. The vulnerability does not require credentials and can be exploited by any network user, exposing sensitive data and potentially enabling account compromise.
Affected Systems
The vulnerability affects the TeamDavid Webbox before Rollout 528. No other versions are listed as affected in the current advisory.
Risk and Exploitability
The CVSS score of 9.2 marks the issue as critical. Because authentication is not required, an attacker can exploit the flaw from any system that can reach the vulnerable URL, making remote exploitation straightforward. The EPSS score of 0.0032 indicates a very low, but non‑zero exploitation probability. The vulnerability is not yet in the CISA KEV list, but the impact warrants immediate attention.
OpenCVE Enrichment