CVE-2026-54214
Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL parameter, which allows
CVSS
—
Sin CVSS
EPSS
0.5%
p38
KEV
—
Exploit Today
11
0-100
Publicado: 7 ago 2026 · Última mod.: 7 ago 2026 · CWE-601
Sin historial EPSS suficiente todavía.
Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL parameter, which allows arbitrary modification of the Content-Type header in HTTP responses. Because the parameter does not properly restrict control characters such as URL-encoded newlines (“%0a”) or colons, attackers can inject additional headers including extra Location headers into the server’s response. This results e.g. in an open redirect vulnerability. This issue affects TeamDavid through Rollout 524.