HTTP Header Injection Vulnerability in Tobit Laboratories AG's Webbox Application
CVE-2026-54214

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-54214?

The TeamDavid's Webbox application developed by Tobit Laboratories AG is susceptible to an HTTP header injection flaw due to insufficient parameter validation for the 'cType' URL parameter. This vulnerability allows attackers to manipulate the Content-Type header in HTTP responses by injecting arbitrary values, including control characters such as URL-encoded newlines and colons. As a result, malicious users can introduce additional headers into the server responses, leading to potential open redirect issues and unauthorized behavior. The affected version is Rollout 524 and it is crucial for organizations using this application to assess their security posture and update accordingly.

Affected Version(s)

TeamDavid 0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dario Weiss of InfoGuard Labs
.