Weak Access Controls in Thinkware U3000 TCP Service
CVE-2026-101053
6.9MEDIUM
What is CVE-2026-101053?
A vulnerability exists in the Thinkware U3000 up to version 1.02.04, specifically in the TCP Service's file handling functionality. This flaw pertains to the PUT_FILE operation within the /tmp/wpa_supplicant.conf file, where improper access controls can be exploited. An attacker could manipulate the argument path to gain unauthorized access to sensitive files. The possibility of remote exploitation is particularly concerning, especially as this vulnerability has been publicly disclosed with no response from the vendor despite early communication about the issue.
Affected Version(s)
U3000 1.02.04
