Impact
TVU Networks Receiver/Transceiver devices running firmware earlier than 7.9 are vulnerable to an authentication bypass at the web management login endpoint POST /tvu/Login. An attacker can send a request with an empty or missing UserName field, and the server will issue a valid session cookie regardless of the password. This flaw grants full administrative control of the device’s web interface, enabling the attacker to modify settings, initiate data streams, or potentially disrupt service.
Affected Systems
The vulnerability affects TVU Networks Receiver / Transceiver devices with firmware versions before v7.9. No other product or version information is disclosed.
Risk and Exploitability
The flaw carries a CVSS score of 9.3, indicating critical severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Because the attack requires only a crafted HTTP request to the exposed login endpoint, it is likely exploitable remotely over the network without additional privileges or authentication. The absence of client‑side validation makes the attack trivial for automated tools.
OpenCVE Enrichment