AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-54214

MEDIUM · CVSS 5.3 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection via the "cType" URL parameter, allowing attackers to manipulate the Content-Type header in HTTP responses. This flaw can lead to open redirect vulnerabilities, potentially compromising user trust and redirecting users to malicious sites. Organizations using affected versions of TeamDavid should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-54214
Severity
MEDIUM
CVSS
5.3
EPSS
0.34%

Original NVD Description

Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL parameter, which allows arbitrary modification of the Content-Type header in HTTP responses. Because the parameter does not properly restrict control characters such as URL-encoded newlines (“%0a”) or colons, attackers can inject additional headers including extra Location headers into the server’s response. This results e.g. in an open redirect vulnerability. This issue affects TeamDavid through Rollout 524.