CVE-2026-54199
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Aug 07, 2026
Vendor
unknown
Description
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the request body in the application's link storing functionality (//ServerClient_celink.htm), which is appended to the redirect target in the 302 HTTP response. If a line feed is added, this will also be added to the redirect link, resulting in the ability to control the response headers.Β This issue affects TeamDavid through Rollout 524.