Description
TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain a missing authentication vulnerability that allows remote unauthenticated attackers to read sensitive device information and modify device configuration via unprotected REST API endpoints on port 8288. Attackers can send unauthenticated GET requests to disclose network configuration, firmware details, and cloud service information, or issue POST requests to endpoints such as /Setting3/API/API/v1/LocalNetwork/DNS to alter DNS settings and enable man-in-the-middle attacks on outbound connections to TVU cloud infrastructure.
Published: 2026-10-08
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Remote configuration modification
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a missing authentication flaw in TVU Networks Receiver/Transceiver devices that allows an attacker to send unauthenticated REST API requests over port 8288 to read device configuration, firmware details, and cloud service information. It also permits the modification of critical settings such as DNS, which can be leveraged to orchestrate man‑in‑the‑middle attacks on outbound connections to TVU cloud infrastructure. The weakness is classified as CWE‑306, indicating that proper authentication checks were absent.

Affected Systems

The affected systems are TVU Networks Receiver/Transceiver devices running any firmware version earlier than 7.9. No specific patch numbers are listed, but the vulnerability applies to all firmware releases prior to 7.9. These devices expose the vulnerable REST API on port 8288.

Risk and Exploitability

The CVSS score of 9.3 indicates a high‑severity vulnerability, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, but its mechanics are straightforward and the required network access is simple: an unauthenticated user can reach the device over the open port. Because the attack does not require any special client credentials, the likelihood of exploitation is high as soon as the device is reachable from the attacker’s network.

Generated by OpenCVE AI on October 8, 2026 at 20:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the device firmware to version 7.9 or newer, which adds required authentication to the REST endpoints.
  • Configure firewall rules or VLAN segmentation to restrict external access to TCP port 8288, allowing only trusted management IPs to reach the device.
  • Disable or block the REST API service on port 8288 if upgrading or segmentation is not feasible, to prevent unauthenticated interaction.

Generated by OpenCVE AI on October 8, 2026 at 20:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain a missing authentication vulnerability that allows remote unauthenticated attackers to read sensitive device information and modify device configuration via unprotected REST API endpoints on port 8288. Attackers can send unauthenticated GET requests to disclose network configuration, firmware details, and cloud service information, or issue POST requests to endpoints such as /Setting3/API/API/v1/LocalNetwork/DNS to alter DNS settings and enable man-in-the-middle attacks on outbound connections to TVU cloud infrastructure.
Title TVU Networks Receiver/Transceiver Missing Authentication via REST API
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T19:26:34.263Z

Reserved: 2026-10-01T18:02:50.083Z

Link: CVE-2026-104076

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T20:17:29.543

Modified: 2026-10-08T21:35:53.890

Link: CVE-2026-104076

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T20:30:18Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function