CVE-2026-54215
Received Received - Intake

Open Redirect Vulnerability in Tobit TeamDavid's Webbox

Vulnerability report for CVE-2026-54215, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: Switzerland Government Common Vulnerability Program

Description

Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An attacker can exploit this vulnerability to craft a URL within the application that, when visited, redirects the user’s browser to an arbitrary third-party site. This can be abused for phishing attacks, where users receive a trusted domain link but are redirected to a phishing website. This issue affects TeamDavid through Rollout 524.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tobit_laboratories_ag teamdavid to 524 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

TeamDavid's Webbox by Tobit Laboratories AG has an open redirect vulnerability in the 'replyUrl' parameter. This allows attackers to create URLs that redirect users to malicious third-party sites while appearing to come from a trusted domain. The issue affects TeamDavid through Rollout 524.

Detection Guidance

To detect this vulnerability, inspect web server logs for unusual redirect patterns involving the 'replyUrl' parameter. Check for URLs containing external domains after TeamDavid's Webbox links. Manually test by appending different 'replyUrl' values to TeamDavid URLs to observe redirects.

Impact Analysis

This vulnerability can be exploited for phishing attacks. Users may click what appears to be a legitimate link from a trusted domain but are redirected to a phishing website designed to steal credentials or install malware. It relies on user trust in the domain and lack of visible redirection.

Compliance Impact

The open redirect vulnerability in Tobit Laboratories AG TeamDavid's Webbox could potentially violate compliance with GDPR and HIPAA by enabling phishing attacks. Attackers may use the trusted domain to trick users into disclosing sensitive information, which could lead to data breaches or unauthorized access to personal data, contravening GDPR's data protection principles and HIPAA's security requirements.

Mitigation Strategies

Immediately update TeamDavid to a version beyond Rollout 524. Implement input validation to restrict 'replyUrl' to trusted domains only. Configure web server rules to block or log suspicious redirect attempts. Educate users about phishing risks from unexpected redirects.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54215. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart