Impact
The vulnerability is a missing authentication flaw in TVU Networks Receiver/Transceiver devices that allows an attacker to send unauthenticated REST API requests over port 8288 to read device configuration, firmware details, and cloud service information. It also permits the modification of critical settings such as DNS, which can be leveraged to orchestrate man‑in‑the‑middle attacks on outbound connections to TVU cloud infrastructure. The weakness is classified as CWE‑306, indicating that proper authentication checks were absent.
Affected Systems
The affected systems are TVU Networks Receiver/Transceiver devices running any firmware version earlier than 7.9. No specific patch numbers are listed, but the vulnerability applies to all firmware releases prior to 7.9. These devices expose the vulnerable REST API on port 8288.
Risk and Exploitability
The CVSS score of 9.3 indicates a high‑severity vulnerability, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, but its mechanics are straightforward and the required network access is simple: an unauthenticated user can reach the device over the open port. Because the attack does not require any special client credentials, the likelihood of exploitation is high as soon as the device is reachable from the attacker’s network.
OpenCVE Enrichment