Description
TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an authentication bypass vulnerability in the web management login endpoint POST /tvu/Login that allows remote unauthenticated attackers to obtain an administrative session by submitting an empty or absent UserName parameter. Attackers can send a crafted HTTP request directly, bypassing client-side JavaScript validation, to receive a valid session cookie regardless of the password value and gain full administrative control of the device's web management interface.
Published: 2026-10-08
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Authentication Bypass allowing remote administrative session creation
Action: Patch Immediately
AI Analysis

Impact

TVU Networks Receiver/Transceiver devices running firmware earlier than 7.9 are vulnerable to an authentication bypass at the web management login endpoint POST /tvu/Login. An attacker can send a request with an empty or missing UserName field, and the server will issue a valid session cookie regardless of the password. This flaw grants full administrative control of the device’s web interface, enabling the attacker to modify settings, initiate data streams, or potentially disrupt service.

Affected Systems

The vulnerability affects TVU Networks Receiver / Transceiver devices with firmware versions before v7.9. No other product or version information is disclosed.

Risk and Exploitability

The flaw carries a CVSS score of 9.3, indicating critical severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Because the attack requires only a crafted HTTP request to the exposed login endpoint, it is likely exploitable remotely over the network without additional privileges or authentication. The absence of client‑side validation makes the attack trivial for automated tools.

Generated by OpenCVE AI on October 8, 2026 at 20:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the device firmware to version 7.9 or later to eliminate the authentication bypass flaw
  • If a firmware upgrade is not yet available, isolate the device from untrusted networks by applying firewall rules to block inbound traffic to the web management port
  • Enable network segmentation and enforce VLAN isolation so that only trusted hosts can reach the management interface

Generated by OpenCVE AI on October 8, 2026 at 20:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an authentication bypass vulnerability in the web management login endpoint POST /tvu/Login that allows remote unauthenticated attackers to obtain an administrative session by submitting an empty or absent UserName parameter. Attackers can send a crafted HTTP request directly, bypassing client-side JavaScript validation, to receive a valid session cookie regardless of the password value and gain full administrative control of the device's web management interface.
Title TVU Networks Receiver/Transceiver Authentication Bypass via /tvu/Login
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T19:24:25.801Z

Reserved: 2026-10-01T18:02:50.083Z

Link: CVE-2026-104075

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T20:17:29.377

Modified: 2026-10-08T21:35:53.890

Link: CVE-2026-104075

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T20:30:18Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel