Security Advisory

CVE-2026-54213

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-07 09:47:34
Last updated 2026-08-07 13:17:54
Assigner NCSC.ch
CVSS score not scored
State PUBLISHED

Description

Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/internalRestart) is accessed. This endpoint is accessible to unauthenticated users over the public Internet. Instead of “restarting”, the server shuts completely down. As a result, a remote attacker can trigger a persistent denial of service by shutting down the web server without requiring authentication. Recovery requires manual administrator intervention to restart the service. This issue affects TeamDavid through Rollout 524.