CVE-2026-54199EPSS p17.9%
CVE-2026-54199CVE-2026-54199
Description
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the
request body in the application's link storing functionality
(//ServerClient_celink.htm), which is appended to the redirect target in
the 302 HTTP response. If a line feed is added, this will also be added
to the redirect link, resulting in the ability to control the response
headers. This issue affects TeamDavid through Rollout 524.
Scoring
| EPSS | 0.26% probability of exploitation · percentile 17.9% · 2026-08-08T12:02:54Z |
| Last modified | 2026-08-07 |