CVE-2026-54215
TeamDavid: Open Redirect via the 'replyUrl' parameter
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An attacker can exploit this vulnerability to craft a URL within the application that, when visited, redirects the user’s browser to an arbitrary third-party site. This can be abused for phishing attacks, where users receive a trusted domain link but are redirected to a phishing website. This issue affects TeamDavid through Rollout 524.
| CWE | CWE-601 |
| Vendor | tobit laboratories ag |
| Product | teamdavid |
| Published | Aug 7, 2026 |
| Last Updated | Aug 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for tobit laboratories ag teamdavid
Be the first to know when new unknown vulnerabilities affecting tobit laboratories ag teamdavid are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Tobit Laboratories AG / TeamDavid
0 ≤ Rollout 524
References
Credits
Dario Weiss of InfoGuard Labs