Improper Access Controls in Thinkware U3000's TCP Service
CVE-2026-101054
Key Information:
Badges
What is CVE-2026-101054?
A security flaw has been detected in the Thinkware U3000's TCP Service that affects the function get_file in the /tmp/wpa_supplicant.conf file. This vulnerability allows attackers to manipulate access controls, potentially enabling unauthorized remote access. Public exploits are available, and the vendor has not responded to disclosures regarding this issue, raising concerns about timely remediation. Users are advised to be aware of their system's version and apply necessary security measures.
Affected Version(s)
U3000 1.02.04
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
