在 Thinkware U3000(版本最高至 1.02.04)中发现了一个漏洞。该漏洞影响 TCP Service 组件中对文件 的 PUT_FILE 函数。通过操纵参数 path,可能导致访问控制不当。攻击者可以远程发起攻击。该利用代码已公开披露,可能被他人利用。厂商在漏洞披露初期即已收到通知,但未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101054 | 5.3 MEDIUM | Thinkware U3000 TCP Service wpa_supplicant.conf get_file access control |
| CVE-2026-101055 | 5.3 MEDIUM | Thinkware U3000 TCP Service GET_STATUS information disclosure |
No comments yet