CVE-2026-101053
Received Received - Intake

Improper Access Control in Thinkware U3000 Firmware via Path Manipulation

Vulnerability report for CVE-2026-101053, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability was determined in Thinkware U3000 up to 1.02.04. This impacts the function PUT_FILE of the file /tmp/wpa_supplicant.conf of the component TCP Service. Executing a manipulation of the argument path can lead to improper access controls. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
thinkware u3000 to 1.02.04 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-101053 is an arbitrary file write vulnerability in Thinkware U3000 dashcams up to version 1.02.04. It allows unauthenticated attackers to write arbitrary data to any file path on the device via a PUT_FILE command in the TCP control protocol. The attack occurs over ports 7878 and 8787 without encryption.

Detection Guidance

To detect this vulnerability, scan your network for devices running on ports 7878 and 8787, which are used by the Thinkware U3000 dashcam's TCP control protocol. Use tools like nmap to check for open ports: nmap -p 7878,8787 <target_IP>. If these ports are open, further investigation is needed to determine if the device is vulnerable.

Impact Analysis

This vulnerability enables attackers on the local network to overwrite sensitive files like WiFi credentials or execute arbitrary scripts by writing to system directories. It could lead to data theft, device compromise, or unauthorized access to the dashcam's functions.

Compliance Impact

This vulnerability allows unauthorized file writes to sensitive system locations, potentially exposing or altering data like WiFi credentials or system configurations. Such improper access controls could lead to data breaches, violating GDPR's integrity and confidentiality requirements or HIPAA's safeguards for protected health information if the device handles such data.

Mitigation Strategies

Immediately isolate the affected device from your network to prevent remote exploitation. Disable the TCP control protocol ports 7878 and 8787 if possible. Update the device firmware to the latest version if a patch is available. If no patch exists, consider replacing the device with a more secure alternative.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101053. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart