Weak Access Controls in Thinkware U3000 TCP Service
CVE-2026-101053

6.9MEDIUM

Key Information:

Vendor

Thinkware

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-101053?

A vulnerability exists in the Thinkware U3000 up to version 1.02.04, specifically in the TCP Service's file handling functionality. This flaw pertains to the PUT_FILE operation within the /tmp/wpa_supplicant.conf file, where improper access controls can be exploited. An attacker could manipulate the argument path to gain unauthorized access to sensitive files. The possibility of remote exploitation is particularly concerning, especially as this vulnerability has been publicly disclosed with no response from the vendor despite early communication about the issue.

Affected Version(s)

U3000 1.02.04

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

turret (VulDB User)
VulDB CNA Team
.