AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-54215

MEDIUM · CVSS 5.3 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The open redirect vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows attackers to manipulate the "replyUrl" parameter, redirecting users to arbitrary third-party sites. This can facilitate phishing attacks, as users may be misled into believing they are navigating to a trusted domain. Organizations using TeamDavid, particularly those on Rollout 524, should prioritize addressing this vulnerability to protect their users from potential phishing threats.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-54215
Severity
MEDIUM
CVSS
5.3
EPSS
0.27%

Original NVD Description

Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An attacker can exploit this vulnerability to craft a URL within the application that, when visited, redirects the user’s browser to an arbitrary third-party site. This can be abused for phishing attacks, where users receive a trusted domain link but are redirected to a phishing website. This issue affects TeamDavid through Rollout 524.