CVE-2026-54213
Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoin
CVSS
—
Sin CVSS
EPSS
0.7%
p50
KEV
—
Exploit Today
15
0-100
Publicado: 7 ago 2026 · Última mod.: 7 ago 2026 · CWE-284
Sin historial EPSS suficiente todavía.
Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/internalRestart) is accessed. This endpoint is accessible to unauthenticated users over the public Internet. Instead of “restarting”, the server shuts completely down. As a result, a remote attacker can trigger a persistent denial of service by shutting down the web server without requiring authentication. Recovery requires manual administrator intervention to restart the service. This issue affects TeamDavid through Rollout 524.