Tobit Laboratories AG TeamDavid's Webbox application...
Critical severity
Unreviewed
Published
Aug 7, 2026
to the GitHub Advisory Database
•
Updated Sep 7, 2026
Description
Published by the National Vulnerability Database
Aug 7, 2026
Published to the GitHub Advisory Database
Aug 7, 2026
Last updated
Sep 7, 2026
Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be
shut down when a specific endpoint (/internalRestart) is accessed. This
endpoint is accessible to unauthenticated users over the public
Internet. Instead of “restarting”, the server shuts completely down. As a
result, a remote attacker can trigger a persistent denial of service by
shutting down the web server without requiring authentication. Recovery
requires manual administrator intervention to restart the service. This issue affects TeamDavid through Rollout 524.
References