EUVD Vulnerability Catalog
EUVD-2026-54444
Severity: CRITICAL
Base Score: 9.2
CVSS Version: 4.0
Vulnerability Description
Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be
shut down when a specific endpoint (/internalRestart) is accessed. This
endpoint is accessible to unauthenticated users over the public
Internet. Instead of “restarting”, the server shuts completely down. As a
result, a remote attacker can trigger a persistent denial of service by
shutting down the web server without requiring authentication. Recovery
requires manual administrator intervention to restart the service. This issue affects TeamDavid before Rollout 528.
Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
CVSS Vector Analysis
Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
▪
Attack Vector (AV): Network
▪
Attack Complexity (AC): Low
▪
Attack Requirements (AT): None
▪
Privileges Required (PR): None
▪
User Interaction (UI): None
▪
Vulnerability Confidentiality Impact (VC): None
▪
Vulnerability Integrity Impact (VI): None
▪
Vulnerability Availability Impact (VA): High
▪
Subsequent Confidentiality Impact (SC): None
▪
Subsequent Integrity Impact (SI): None
▪
Subsequent Availability Impact (SA): High
Affected Vendors & Systems
Vendor
Tobit Laboratories AG
References & Advisory Links
Metadata Profile
Database Authority
European Union Agency for Cybersecurity (ENISA) EUVD
Assigner
NCSC.ch
EPSS Probability
0.45
Known Aliases
GHSA-wrxj-2wgm-px6x
CVE-2026-54213
Published On
2026-08-07
Last Updated
2026-09-07