在 Thinkware U3000(版本 1.02.04 及之前)中发现了一个安全漏洞。该漏洞影响了 TCP 服务组件中的 GET_STATUS 函数。通过对参数 的操纵,可导致信息泄露。该攻击可远程执行。利用代码已公开,可能被用于发起攻击。厂商已在此漏洞披露前收到通知,但未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101053 | 7.3 HIGH | Thinkware U3000 TCP Service wpa_supplicant.conf PUT_FILE access control |
| CVE-2026-101054 | 5.3 MEDIUM | Thinkware U3000 TCP Service wpa_supplicant.conf get_file access control |
No comments yet