CVE-2026-54213: TeamDavid: Denial of Service via endpoint 'internalRestart'
Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/internalRestart) is accessed. This endpoint is accessible to unauthenticated users over the public Internet. Instead of “restarting”, the server shuts completely down. As a result, a remote attacker can trigger a persistent denial of service by shutting down the web server without requiring authentication. Recovery requires manual administrator intervention to restart the service. This issue affects TeamDavid through Rollout 524.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-54213?
CVE-2026-54213 has a severity rating of 69.
How do I fix CVE-2026-54213?
To mitigate CVE-2026-54213, restrict access to the '/internalRestart' endpoint to authenticated users only.
What impact does CVE-2026-54213 have on TeamDavid Webbox?
CVE-2026-54213 allows unauthenticated users to trigger a denial of service by accessing the '/internalRestart' endpoint.
When was CVE-2026-54213 published?
CVE-2026-54213 was published on August 7, 2026.
Who is affected by CVE-2026-54213?
Any user of TeamDavid Webbox is affected by CVE-2026-54213 due to the exposed endpoint allowing server shutdown.