Impact
This vulnerability allows an unauthenticated user to remotely shut down the TeamDavid Webbox server by accessing the /internalRestart endpoint, which terminates the service rather than restarting it. The impact is a persistent denial of service because the attacker can bring the web server down over the public Internet, and recovery requires manual administrator intervention to restart the service. The weakness is unauthorized access to an internal control function, identified as CWE‑284.
Affected Systems
The affected vendor is Tobit Laboratories AG, product TeamDavid Webbox. The issue has been identified in Rollout 524 and any earlier or current releases that include that rollback. Additional CPE strings are not provided, but any system running that release of TeamDavid is susceptible. No specific version numbers beyond Rollout 524 are offered.
Risk and Exploitability
The CVSS score of 9.2 categorizes this flaw as critical, and although EPSS data is unavailable, the lack of authentication requirement and public Internet exposure make it highly exploitable. Attackers can trigger the denial of service by sending a simple HTTP request to /internalRestart from any network location. The vulnerability does not provide privilege escalation or confidentiality compromise, but the ability to bring down a key service may have significant business impact. The condition of this flaw is not yet listed in CISA KEV, but its severity warrants immediate attention.
OpenCVE Enrichment