CVE-2024-14007 | Shenzhen TVT Digital NVMS-9000 up to 1.3.3 TCP missing authentication (EUVD-2025-199001)
A vulnerability, which was classified as critical, has been found in Shenzhen TVT Digital NVMS-9000 up to 1.3.3. This issue affects the function queryBasicCfg/queryUserList/queryEmailCfg/queryPPPoECfg/queryFTPCfg of the component TCP Handler. The manipulation leads to missing authentication.
This vulnerability is referenced as CVE-2024-14007. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
It is advisable to upgrade the affected component.