Description
Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be
shut down when a specific endpoint (/internalRestart) is accessed. This
endpoint is accessible to unauthenticated users over the public
Internet. Instead of “restarting”, the server shuts completely down. As a
result, a remote attacker can trigger a persistent denial of service by
shutting down the web server without requiring authentication. Recovery
requires manual administrator intervention to restart the service. This issue affects TeamDavid before Rollout 528.

Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
Published: 2026-08-07
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A public, unauthenticated HTTP endpoint named /internalRestart allows a remote user to trigger a shutdown of the TeamDavid Webbox server. When accessed, the server is terminated rather than restarted, resulting in a persistent denial of service. No credentials or special privileges are required; the request can come from any location on the Internet. The flaw is an unauthorized access to an internal control function, corresponding to CWE‑284.

Affected Systems

The affected vendor is Tobit Laboratories AG, product TeamDavid Webbox. The issue has been identified in Rollout 524 and any earlier or current releases that include that rollback. Additional CPE strings are not provided, but any system running that release of TeamDavid is susceptible. No specific version numbers beyond Rollout 524 are offered.

Risk and Exploitability

The CVSS score of 9.2 categorizes this flaw as critical, and the EPSS score of < 1% shows a low but nonzero likelihood of exploitation. The endpoint is publicly exposed and requires no authentication, making it trivially exploitable by a remote attacker. A single HTTP request to /internalRestart will shut down the service, requiring manual administrator intervention to restart. The vulnerability does not provide privilege escalation or confidentiality compromise, but the loss of service can have significant business impact. While the flaw is not currently listed in CISA KEV, its severity warrants close attention.

Generated by OpenCVE AI on September 7, 2026 at 15:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest version of TeamDavid provided by Tobit Laboratories AG that removes or secures the /internalRestart endpoint.
  • If a vendor patch is not immediately available, configure network firewalls or reverse proxies to block all external access to the /internalRestart endpoint and only allow internal network traffic with proper authentication.
  • Monitor application logs for requests to /internalRestart and alert on repeated or unauthorized access attempts.
  • As an interim workaround, remove or rename the /internalRestart route from the deployment configuration to prevent accidental hits until a formal fix is deployed.

Generated by OpenCVE AI on September 7, 2026 at 15:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
References

Mon, 07 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/internalRestart) is accessed. This endpoint is accessible to unauthenticated users over the public Internet. Instead of “restarting”, the server shuts completely down. As a result, a remote attacker can trigger a persistent denial of service by shutting down the web server without requiring authentication. Recovery requires manual administrator intervention to restart the service. This issue affects TeamDavid through Rollout 524. Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/internalRestart) is accessed. This endpoint is accessible to unauthenticated users over the public Internet. Instead of “restarting”, the server shuts completely down. As a result, a remote attacker can trigger a persistent denial of service by shutting down the web server without requiring authentication. Recovery requires manual administrator intervention to restart the service. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
References

Fri, 07 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid
Vendors & Products Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid

Fri, 07 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/internalRestart) is accessed. This endpoint is accessible to unauthenticated users over the public Internet. Instead of “restarting”, the server shuts completely down. As a result, a remote attacker can trigger a persistent denial of service by shutting down the web server without requiring authentication. Recovery requires manual administrator intervention to restart the service. This issue affects TeamDavid through Rollout 524.
Title TeamDavid: Denial of Service via endpoint 'internalRestart'
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


Subscriptions

Tobit Laboratories Ag Teamdavid
cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-09-07T12:59:55.983Z

Reserved: 2026-06-12T09:32:46.514Z

Link: CVE-2026-54213

cve-icon Vulnrichment

Updated: 2026-08-07T13:17:47.557Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T10:16:58.500

Modified: 2026-09-07T13:20:30.487

Link: CVE-2026-54213

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T15:15:17Z

Weaknesses