在 Thinkware U3000(版本 1.02.04 及更早)中发现一个漏洞。该漏洞位于 TCP 服务组件中,具体涉及对 文件的操作,由 函数处理。由于不当的访问控制,攻击者可利用该漏洞进行远程利用。相关利用代码已公开,可能被用于实际攻击。厂商在漏洞披露初期已被通知,但未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101053 | 7.3 HIGH | Thinkware U3000 TCP Service wpa_supplicant.conf PUT_FILE access control |
| CVE-2026-101055 | 5.3 MEDIUM | Thinkware U3000 TCP Service GET_STATUS information disclosure |
No comments yet