Description
Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the
“replyUrl” parameter. An attacker can exploit this vulnerability to
craft a URL within the application that, when visited, redirects the
user’s browser to an arbitrary third-party site. This can be abused for
phishing attacks, where users receive a trusted domain link but are
redirected to a phishing website. This issue affects TeamDavid before Rollout 528.

Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
Published: 2026-08-07
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Open Redirect via replyUrl parameter
Action: Apply Patch
AI Analysis

Impact

Tobit Laboratories AG’s TeamDavid Webbox includes an open redirect vulnerability in the replyUrl query parameter. An attacker can craft a URL that redirects the victim’s browser to an arbitrary third‑party site when accessed through the app. The primary risk is phishing or social‑engineering attacks where users think the link is legitimate but are directed to malicious domains. The issue affects deployments before Rollout 528; after Rollout 528 the functionality is disabled by default and the redirect flaw is no longer exposed.

Affected Systems

The vulnerability affects TeamDavid Webbox installations running a version prior to Rollout 528, released June 30 2026. The affected functionality is disabled by default in Rollout 528 and later releases, so only systems not updated beyond that version remain exposed.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. Exploitation requires only a crafted URL and is sent via the web interface, making it easy for an attacker to use. An EPSS score of 0.00271 indicates a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that it is not widely exploited yet. However, the attack vector is straightforward and could be widely abused if left unattended, especially on versions before Rollout 528 where the function is enabled by default.

Generated by OpenCVE AI on September 7, 2026 at 15:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade TeamDavid to a version that fixes the replyUrl redirect flaw
  • Configure the application to validate or whitelist allowed redirect URLs, rejecting any that do not match the corporate domain
  • Implement a web application firewall rule or redirect filter to block or log unexpected redirects attempted from the replyUrl parameter

Generated by OpenCVE AI on September 7, 2026 at 15:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
References

Mon, 07 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An attacker can exploit this vulnerability to craft a URL within the application that, when visited, redirects the user’s browser to an arbitrary third-party site. This can be abused for phishing attacks, where users receive a trusted domain link but are redirected to a phishing website. This issue affects TeamDavid through Rollout 524. Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An attacker can exploit this vulnerability to craft a URL within the application that, when visited, redirects the user’s browser to an arbitrary third-party site. This can be abused for phishing attacks, where users receive a trusted domain link but are redirected to a phishing website. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
References

Fri, 07 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid
Vendors & Products Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid

Fri, 07 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An attacker can exploit this vulnerability to craft a URL within the application that, when visited, redirects the user’s browser to an arbitrary third-party site. This can be abused for phishing attacks, where users receive a trusted domain link but are redirected to a phishing website. This issue affects TeamDavid through Rollout 524.
Title TeamDavid: Open Redirect via the 'replyUrl' parameter
Weaknesses CWE-601
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Tobit Laboratories Ag Teamdavid
cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-09-07T13:01:19.082Z

Reserved: 2026-06-12T09:32:46.514Z

Link: CVE-2026-54215

cve-icon Vulnrichment

Updated: 2026-08-07T11:25:06.347Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T10:16:58.763

Modified: 2026-09-07T14:16:52.097

Link: CVE-2026-54215

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T15:45:17Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')