top of page
perceptive_background_267k.jpg

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where t…

Published:

3 August 2026 at 00:00:00

Alert date:

3 August 2026 at 17:06:10

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications, Identity & Access

Telenia Software TVox versions 26.5.3 and prior (26.x) and 24.9.21 and prior (24.x) contain an authentication bypass vulnerability in set_env.php. The vulnerable function redirectToLoginAdminIRequestHaveAccessToken() derives the current page name from the PHP_SELF variable and skips authentication if the value matches 'login_admin.php'. Attackers can exploit this by appending '/login_admin.php' to any target PHP script path, causing the authentication check to be bypassed. This allows unauthenticated access to all PHP scripts located under the manager HTML directory. The vulnerability requires no authentication or special privileges to exploit, making it highly critical. Organizations using affected versions of Telenia TVox should apply patches or mitigations immediately.

Technical details

Mitigation steps:

Affected products:

Telenia Software TVox 26.5.3
Telenia Software TVox 24.9.21

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page