<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>TVU Networks - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/tvu-networks/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 21:59:16 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/tvu-networks/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in TVU Networks Receiver and Transceiver Devices</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2026-104075/</link><pubDate>Thu, 08 Oct 2026 21:59:16 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2026-104075/</guid><description>TVU Networks Receiver and Transceiver firmware versions prior to 7.9 contain an authentication bypass vulnerability in the /tvu/Login endpoint, allowing unauthenticated attackers to gain administrative sessions.</description><content:encoded><![CDATA[<p>TVU Networks Receiver and Transceiver devices running firmware versions before 7.9 are susceptible to an authentication bypass vulnerability (CVE-2026-104075). The vulnerability exists within the web management login interface at the POST /tvu/Login endpoint. Remote, unauthenticated attackers can successfully authenticate by submitting an HTTP request with an empty or absent UserName parameter. Because the application logic fails to validate the presence of the username before processing the request, the server issues a valid administrative session cookie regardless of whether a password is provided. This flaw allows attackers to bypass standard login procedures and gain full administrative control over the affected device's web management console. Given the nature of these devices in media transport workflows, unauthorized access could lead to the interception or manipulation of broadcast feeds and unauthorized configuration changes.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full administrative access to the affected TVU Networks device. Attackers can modify system configurations, manage broadcast streams, or pivot to internal networks where these devices are deployed. This vulnerability targets broadcast infrastructure and media production environments, posing a significant risk to the integrity and confidentiality of broadcast operations.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security operations and IT teams:</p>
<ul>
<li>Patch all TVU Networks Receiver and Transceiver devices to firmware version 7.9 or later immediately.</li>
<li>Restrict access to the web management interface of these devices to authorized management subnets via firewall rules.</li>
<li>Monitor web server access logs for anomalous POST requests to /tvu/Login originating from unauthorized internal or external IP addresses.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>authentication-bypass</category><category>cve</category><category>network-security</category></item></channel></rss>