Impact
Tobit Laboratories AG’s TeamDavid Webbox includes an open redirect vulnerability in the replyUrl query parameter. An attacker can craft a URL that redirects the victim’s browser to an arbitrary third‑party site when accessed through the app. The primary risk is phishing or social‑engineering attacks where users think the link is legitimate but are directed to malicious domains. The issue affects deployments before Rollout 528; after Rollout 528 the functionality is disabled by default and the redirect flaw is no longer exposed.
Affected Systems
The vulnerability affects TeamDavid Webbox installations running a version prior to Rollout 528, released June 30 2026. The affected functionality is disabled by default in Rollout 528 and later releases, so only systems not updated beyond that version remain exposed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. Exploitation requires only a crafted URL and is sent via the web interface, making it easy for an attacker to use. An EPSS score of 0.00271 indicates a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that it is not widely exploited yet. However, the attack vector is straightforward and could be widely abused if left unattended, especially on versions before Rollout 528 where the function is enabled by default.
OpenCVE Enrichment