CVE-2026-54215 MEDIUM

CVE-2026-54215: TeamDavid: Open Redirect via the 'replyUrl' parameter

Vendor Tobit Laboratories Ag
Product TeamDavid
Weakness CWE-601 · Open redirect
Published August 7, 2026
Last update August 7, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An attacker can exploit this vulnerability to craft a URL within the application that, when visited, redirects the user’s browser to an arbitrary third-party site. This can be abused for phishing attacks, where users receive a trusted domain link but are redirected to a phishing website. This issue affects TeamDavid through Rollout 524.

Key dates

02Disclosure timeline

August 7, 2026 CVE published
August 7, 2026 Record updated

Related vulnerabilities

04Related CVE