GHSA-6m79-2fc6-x428CriticalCVSS 9.8
TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an...
🔗 CVE IDs covered (1)
📋 Description
TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an authentication bypass vulnerability in the web management login endpoint POST /tvu/Login that allows remote unauthenticated attackers to obtain an administrative session by submitting an empty or absent UserName parameter. Attackers can send a crafted HTTP request directly, bypassing client-side JavaScript validation, to receive a valid session cookie regardless of the password value and gain full administrative control of the device's web management interface.
🔗 References (4)
- https://nvd.nist.gov/vuln/detail/CVE-2026-104075
- https://code-white.com/public-vulnerability-list/#authentication-bypass-in-tvu-receiver-transceiver-web-management-interface
- https://www.vulncheck.com/advisories/tvu-networks-receiver-transceiver-authentication-bypass-via-tvu-login
- https://github.com/advisories/GHSA-6m79-2fc6-x428