CVE-2026-54214 Details
Description
Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL parameter, which allows arbitrary modification of the Content-Type header in HTTP responses. Because the parameter does not properly restrict control characters such as URL-encoded newlines (“%0a”) or colons, attackers can inject additional headers including extra Location headers into the server’s response. This results e.g. in an open redirect vulnerability. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
A vulnerability in Tobit Laboratories AG TeamDavid's Webbox application allows HTTP header injection via the 'cType' URL parameter. This flaw, present in TeamDavid through Rollout 524, arises because the parameter fails to properly sanitize control characters, such as URL-encoded newlines and colons. As a result, attackers can manipulate the Content-Type header and inject additional headers, including Location headers, into the server's response. This exploitation can lead to open redirect vulnerabilities, where users are redirected to malicious sites, potentially causing phishing attacks.
Users are advised to update to the latest version of TeamDavid, as the most recent release appears to address these vulnerabilities. For organizations, consider placing the TeamDavid web server behind a VPN or a reverse proxy that filters requests and blocks access to non-essential endpoints.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 7, 2026CISA-ADP
Assessed Aug 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/ | CISA-ADP | BundleExploitRemedyTechnical Analysis |
| https://chayns.net/77892-10814/tapp/763210?postId=11454 | [email protected] | |
| https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/ | [email protected] | BundleExploitRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Tobit Laboratories AG TeamDavid | <= 524 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 7, 2026 | CVE Modified | [email protected] |
| Sep 7, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2026 | New CVE Received | [email protected] |
Volerion