CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-54215

unknowncovered by 1 sourcefirst seen 2026-08-07
Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An attacker can exploit this vulnerability to craft a URL within the application that, when visited, redirects the user’s browser to an arbitrary third-party site. This can be abused for phishing attacks, where users receive a trusted domain link but are redirected to a phishing website. This issue affects TeamDavid through Rollout 524.

⚡ Watch CVE-2026-54215

Get an email if CVE-2026-54215 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-54215

CVE.org record

Embed the live status

CVE-2026-54215 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-54215 status](https://www.csirts.com/badge/CVE-2026-54215)](https://www.csirts.com/cve/CVE-2026-54215)