AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-54213

CRITICAL · CVSS 9.2 EPSS 0.45%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Webbox application from Tobit Laboratories AG contains a critical vulnerability that allows unauthenticated users to access the /internalRestart endpoint, leading to a complete shutdown of the server instead of a restart. This exposes the application to remote attackers who can cause a persistent denial of service, requiring manual intervention for recovery. Organizations using TeamDavid, particularly those on Rollout 524, should prioritize immediate remediation to mitigate this risk.

CVE
CVE-2026-54213
Severity
CRITICAL
CVSS
9.2
EPSS
0.45%

Original NVD Description

Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/internalRestart) is accessed. This endpoint is accessible to unauthenticated users over the public Internet. Instead of “restarting”, the server shuts completely down. As a result, a remote attacker can trigger a persistent denial of service by shutting down the web server without requiring authentication. Recovery requires manual administrator intervention to restart the service. This issue affects TeamDavid through Rollout 524.