CVE-2026-54214EPSS p26.1%
CVE-2026-54214CVE-2026-54214
Description
Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the
“cType” URL parameter, which allows arbitrary modification of the
Content-Type header in HTTP responses. Because the parameter does not
properly restrict control characters such as URL-encoded newlines
(“%0a”) or colons, attackers can inject additional headers including
extra Location headers into the server’s response. This results e.g. in
an open redirect vulnerability. This issue affects TeamDavid through Rollout 524.
Scoring
| EPSS | 0.34% probability of exploitation · percentile 26.1% · 2026-08-08T12:02:54Z |
| Last modified | 2026-08-07 |