CVE-2026-104075: TVU Networks Receiver/Transceiver Authentication Bypass via /tvu/Login

Published Oct 8, 2026
·
Updated

TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an authentication bypass vulnerability in the web management login endpoint POST /tvu/Login that allows remote unauthenticated attackers to obtain an administrative session by submitting an empty or absent UserName parameter. Attackers can send a crafted HTTP request directly, bypassing client-side JavaScript validation, to receive a valid session cookie regardless of the password value and gain full administrative control of the device's web management interface.

Affected Software

1 affected component
TVU Networks Receiver/Transceiver<7.9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade TVU Networks Receiver/Transceiver to a version that resolves this vulnerability.

    Fixed in 7.9

Event History

Oct 8, 2026
CVE Published
via MITRE·07:24 PM
Data Sourced
via MITRE·07:24 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which systems are affected?

TVU Networks Receiver/Transceiver devices running firmware earlier than version 7.9 are affected. The exposed component is the device web management interface.

2

What does an attacker need to exploit this issue?

An attacker only needs network access to the web management login endpoint. No credentials, user interaction, or valid password are required; the attacker can submit an empty or omitted UserName parameter to POST /tvu/Login.

3

What access can successful exploitation provide?

Successful exploitation returns a valid administrative session cookie. This gives the attacker full administrative control of the device's web management interface.

4

How can administrators determine whether a device may be vulnerable?

Check the device firmware version. Devices running a version before 7.9 may be vulnerable, particularly if their web management interface is reachable by untrusted networks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203