Unauthenticated attackers can read sensitive data from TVU Networks Receiver/Transceiver devices running firmware before 7.9, and can change device settings such as DNS through unprotected REST API endpoints on port 8288.
What Is It
CVE-2026-104076 is a missing authentication vulnerability (CWE-306) in the TVU Networks Receiver/Transceiver devices. Several REST API endpoints on port 8288 do not require authentication. A remote attacker can send GET requests to these endpoints to read the device's network configuration, firmware details and cloud service information. The attacker can also send POST requests to change the device's configuration. One example is /Setting3/API/API/v1/LocalNetwork/DNS, which changes the DNS settings.
VulnCheck published the CVE on 2026-10-08. Its NVD status is currently "Deferred."
Why It Matters
VulnCheck scores the flaw as Critical:
- CVSS 3.1: 9.1 (
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) - CVSS 4.0: 9.3
An attacker needs no credentials, no user interaction and no special conditions. Network access to port 8288 is enough. Both confidentiality and integrity impacts are rated high.
Changing the DNS settings has a further effect. According to the NVD description, it lets an attacker carry out man-in-the-middle attacks on the device's outbound connections to TVU's cloud infrastructure. That turns a configuration exposure into a way to intercept or tamper with the device's cloud traffic.
KEV status: As of 2026-10-08, the CISA Known Exploited Vulnerabilities (KEV) Catalog contains no entry for this CVE. KEV does not currently confirm active exploitation.
What's Vulnerable
- Vendor: TVU Networks
- Product: TVU Receiver / Transceiver
- Affected versions: All firmware versions before 7.9
- Exposed service: REST API on port 8288
The NVD record lists no CPE entries.
Patch Status
The affected range ends at firmware version 7.9, so versions 7.9 and later are not listed as affected. Organizations running these devices should confirm their firmware versions and upgrade to 7.9 or later.
There is no CISA KEV entry, so CISA has not issued a required action or due date. The supplied data does not include a vendor advisory or workaround. If an upgrade has to wait, consider limiting network access to port 8288 as an interim exposure-reduction step. This recommendation comes from the description of the exposed service, not from a vendor statement.