CVE-2026-54215: TeamDavid: Open Redirect via the 'replyUrl' parameter
Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An attacker can exploit this vulnerability to craft a URL within the application that, when visited, redirects the user’s browser to an arbitrary third-party site. This can be abused for phishing attacks, where users receive a trusted domain link but are redirected to a phishing website. This issue affects TeamDavid through Rollout 524.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-54215?
CVE-2026-54215 has a risk rating of 21.
How do I fix CVE-2026-54215?
To fix CVE-2026-54215, validate and sanitize the 'replyUrl' parameter to ensure it does not redirect to untrusted sites.
What risks are associated with CVE-2026-54215?
CVE-2026-54215 can be used by attackers to direct users to malicious websites, leading to potential phishing attacks or malware installation.
Which software is affected by CVE-2026-54215?
CVE-2026-54215 specifically affects TeamDavid's Webbox software.
When was CVE-2026-54215 published?
CVE-2026-54215 was published on August 7, 2026.