CVE-2026-54215EPSS p19.0%
CVE-2026-54215CVE-2026-54215
Description
Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the
“replyUrl” parameter. An attacker can exploit this vulnerability to
craft a URL within the application that, when visited, redirects the
user’s browser to an arbitrary third-party site. This can be abused for
phishing attacks, where users receive a trusted domain link but are
redirected to a phishing website. This issue affects TeamDavid through Rollout 524.
Scoring
| EPSS | 0.27% probability of exploitation · percentile 19.0% · 2026-08-08T12:02:54Z |
| Last modified | 2026-08-07 |