Authentication Bypass in TVU Networks Receiver/Transceiver Devices
CVE-2026-104075
9.3CRITICAL
What is CVE-2026-104075?
TVU Networks Receiver and Transceiver devices running firmware versions earlier than 7.9 are susceptible to an authentication bypass vulnerability. This flaw resides in the web management login interface at the endpoint POST /tvu/Login, allowing remote attackers to gain unauthorized access. By submitting an empty or missing UserName parameter, attackers can bypass client-side validation and receive a valid session cookie. Consequently, this grants them complete control over the device’s administrative web management interface, posing significant risks to user security and device integrity. For more information, refer to sources from CODE WHITE and VulnCheck.
Affected Version(s)
TVU Receiver / Transceiver 0 < 7.9
