Description
Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the
“replyUrl” parameter. An attacker can exploit this vulnerability to
craft a URL within the application that, when visited, redirects the
user’s browser to an arbitrary third-party site. This can be abused for
phishing attacks, where users receive a trusted domain link but are
redirected to a phishing website. This issue affects TeamDavid through Rollout 524.
Published: 2026-08-07
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Tobit Laboratories AG’s TeamDavid Webbox includes an open redirect vulnerability in the replyUrl query parameter. An attacker can construct a URL that, when accessed through the application, redirects the victim’s browser to any arbitrary third‑party site. The primary risk is phishing or social‑engineering attacks where users perceive the link as legitimate but are directed to malicious domains.

Affected Systems

The vulnerability affects TeamDavid distributed through Rollout 524. This applies to installations of TeamDavid Webbox that have not yet been updated beyond that version.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. Exploitation requires only a crafted URL and is sent via the web interface, making it easy for an attacker to use. No EPSS estimate is available and the vulnerability is not listed in CISA’s KEV catalog, suggesting that it is not widely exploited yet, but the attack vector is straightforward and could be widely abused if left unattended.

Generated by OpenCVE AI on August 7, 2026 at 11:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade TeamDavid to a version that fixes the replyUrl redirect flaw
  • Configure the application to validate or whitelist allowed redirect URLs, rejecting any that do not match the corporate domain
  • Implement a web application firewall rule or redirect filter to block or log unexpected redirects attempted from the replyUrl parameter

Generated by OpenCVE AI on August 7, 2026 at 11:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid
Vendors & Products Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid

Fri, 07 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An attacker can exploit this vulnerability to craft a URL within the application that, when visited, redirects the user’s browser to an arbitrary third-party site. This can be abused for phishing attacks, where users receive a trusted domain link but are redirected to a phishing website. This issue affects TeamDavid through Rollout 524.
Title TeamDavid: Open Redirect via the 'replyUrl' parameter
Weaknesses CWE-601
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Tobit Laboratories Ag Teamdavid
cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-08-07T11:25:12.256Z

Reserved: 2026-06-12T09:32:46.514Z

Link: CVE-2026-54215

cve-icon Vulnrichment

Updated: 2026-08-07T11:25:06.347Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T11:30:03Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')