Impact
Tobit Laboratories AG’s TeamDavid Webbox includes an open redirect vulnerability in the replyUrl query parameter. An attacker can construct a URL that, when accessed through the application, redirects the victim’s browser to any arbitrary third‑party site. The primary risk is phishing or social‑engineering attacks where users perceive the link as legitimate but are directed to malicious domains.
Affected Systems
The vulnerability affects TeamDavid distributed through Rollout 524. This applies to installations of TeamDavid Webbox that have not yet been updated beyond that version.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. Exploitation requires only a crafted URL and is sent via the web interface, making it easy for an attacker to use. No EPSS estimate is available and the vulnerability is not listed in CISA’s KEV catalog, suggesting that it is not widely exploited yet, but the attack vector is straightforward and could be widely abused if left unattended.
OpenCVE Enrichment