CVE-2026-104075 — TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an authentication bypass vulnerability in the web management …
Description
TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an authentication bypass vulnerability in the web management login endpoint POST /tvu/Login that allows remote unauthenticated attackers to obtain an administrative session by submitting an empty or absent UserName parameter. Attackers can send a crafted HTTP request directly, bypassing client-side JavaScript validation, to receive a valid session cookie regardless of the password value and gain full administrative control of the device's web management interface.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCritical severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
AT
None
Attack Requirements
PR
None
Privileges Required
UI
None
User Interaction
VC
High
Confidentiality (Vulnerable System)
VI
High
Integrity (Vulnerable System)
VA
High
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
References
Related threats
same CWE or vendorCVE-2026-107361 — The Arkime live capture service (arkime-live) in Malcolm runs with network_mode: host, exposing port 8005 on all network interfaces (viewHost=0.0.0…
CVE-2026-107361 · 4h ago
CVE-2026-94585 — An authentication bypass vulnerability exists in the web management interface of Brocade Fabric OS versions before 9.2.2d running on the MXG610 pla…
CVE-2026-94585 · 17h ago
CVE-2026-107194 — Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "…
CVE-2026-107194 · 1d ago
CVE-2026-19572 — A security vulnerability has been identified in FlexNet Publisher lmadmin.
CVE-2026-19572 · 2d ago
CVE-2026-39793 — Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions.
CVE-2026-39793 · 3d ago
CVE-2026-39769 — Unauthenticated Broken Authentication in Graphina <= 3.1.12 versions.
CVE-2026-39769 · 3d ago