VYPR

Webbox

by Tobit Laboratories AG

CVEs (5)

  • CVE-2026-54213CriAug 7, 2026
    risk 0.60cvss epss

    Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/internalRestart) is accessed. This endpoint is accessible to unauthenticated users over the public Internet. Instead of…

  • CVE-2026-54209HigAug 7, 2026
    risk 0.58cvss epss

    Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including the string "(editini)" in the file path, writing the new password to the specified "Archive.ini" file. However, the application does not verify that the…

  • CVE-2026-54207MedAug 7, 2026
    risk 0.41cvss epss

    Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The server processes these paths without validation, resulting in…

  • CVE-2026-54216MedAug 7, 2026
    risk 0.34cvss epss

    Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) vulnerability. By sending a specially crafted link including an arbitrary path, an XSS payload or the parameter “EntryInfo”, and the parameter…

  • CVE-2026-12071MedAug 7, 2026
    risk 0.34cvss epss

    The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input, which is appended to the redirect target in a 302 HTTP response. By using URL-encoded characters such as “%2e” (representing a dot), an attacker can manipulate the…