HTTP Header Injection Vulnerability in Tobit Laboratories AG's Webbox Application
CVE-2026-54214
5.3MEDIUM
What is CVE-2026-54214?
The TeamDavid's Webbox application developed by Tobit Laboratories AG is susceptible to an HTTP header injection flaw due to insufficient parameter validation for the 'cType' URL parameter. This vulnerability allows attackers to manipulate the Content-Type header in HTTP responses by injecting arbitrary values, including control characters such as URL-encoded newlines and colons. As a result, malicious users can introduce additional headers into the server responses, leading to potential open redirect issues and unauthorized behavior. The affected version is Rollout 524 and it is crucial for organizations using this application to assess their security posture and update accordingly.
Affected Version(s)
TeamDavid 0
