Impact
Tobit Laboratories AG’s TeamDavid Webbox is vulnerable to HTTP header injection through the "cType" URL parameter. The parameter is not sanitized for control characters such as URL‑encoded newlines (%%0a) or colons, allowing attackers to inject arbitrary HTTP headers, including additional Location headers. This flaw can be abused to redirect victims to malicious sites, effectively creating an open redirect vulnerability. The impact is a compromise of user experience and potential phishing attacks, but it does not grant direct system compromise or data exfiltration.
Affected Systems
The affected product is Tobit Laboratories AG TeamDavid, specifically versions before Rollout 528. No further sub‑versions are listed as affected; users should assume all releases prior to that rollout are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 categorizes the vulnerability as Medium. The EPSS score of < 1% indicates a very low but nonzero exploitation probability. Because the flaw requires only a crafted HTTP request, the risk of exploitation may be higher in organizations with exposed Webbox instances. The issue is not included in the CISA KEV catalog, suggesting no known widespread exploitation yet. Starting with Rollout 528, the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality, reducing risk for upgraded installations.
OpenCVE Enrichment