Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-54215

Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-601 Redireccionamiento de URL a sitio no confiable (Open Redirect)
Fecha de publicación:
07/08/2026
Última modificación:
07/08/2026

Descripción

*** Pendiente de traducción *** Tobit Laboratories AG TeamDavid&amp;#39;s Webbox contains an open redirect vulnerability via the <br /> “replyUrl” parameter. An attacker can exploit this vulnerability to <br /> craft a URL within the application that, when visited, redirects the <br /> user’s browser to an arbitrary third-party site. This can be abused for <br /> phishing attacks, where users receive a trusted domain link but are <br /> redirected to a phishing website. This issue affects TeamDavid through Rollout 524.