Impact
A public, unauthenticated HTTP endpoint named /internalRestart allows a remote user to trigger a shutdown of the TeamDavid Webbox server. When accessed, the server is terminated rather than restarted, resulting in a persistent denial of service. No credentials or special privileges are required; the request can come from any location on the Internet. The flaw is an unauthorized access to an internal control function, corresponding to CWE‑284.
Affected Systems
The affected vendor is Tobit Laboratories AG, product TeamDavid Webbox. The issue has been identified in Rollout 524 and any earlier or current releases that include that rollback. Additional CPE strings are not provided, but any system running that release of TeamDavid is susceptible. No specific version numbers beyond Rollout 524 are offered.
Risk and Exploitability
The CVSS score of 9.2 categorizes this flaw as critical, and the EPSS score of < 1% shows a low but nonzero likelihood of exploitation. The endpoint is publicly exposed and requires no authentication, making it trivially exploitable by a remote attacker. A single HTTP request to /internalRestart will shut down the service, requiring manual administrator intervention to restart. The vulnerability does not provide privilege escalation or confidentiality compromise, but the loss of service can have significant business impact. While the flaw is not currently listed in CISA KEV, its severity warrants close attention.
OpenCVE Enrichment