CVE-2026-101054
Received Received - Intake

Improper Access Control in Thinkware U3000 Firmware

Vulnerability report for CVE-2026-101054, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability was identified in Thinkware U3000 up to 1.02.04. Affected is the function get_file of the file /tmp/wpa_supplicant.conf of the component TCP Service. The manipulation leads to improper access controls. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
thinkware u3000 to 1.02.04 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Thinkware U3000 dashcam, allowing unauthenticated network clients to read arbitrary files on the device. It involves the TCP control protocol running on ports 7878 and 8787 without authentication or encryption. Attackers can use commands like LS and GET_FILE to list and read files, including sensitive data like WiFi credentials stored in /tmp/wpa_supplicant.conf.

Detection Guidance

To detect this vulnerability, check if your Thinkware U3000 dashcam is running firmware version 1.02.04 or earlier. Scan for open ports 7878 and 8787 on the device. Use commands like 'nc <device_ip> 7878' to connect and attempt a session handshake with START_SESSION, SET_CLNT_INFO, and APP_CONNECT commands. If successful without authentication, the device is vulnerable.

Impact Analysis

An attacker on the same network could access recorded videos, WiFi credentials, or any file on the device. This could lead to privacy breaches, unauthorized access to sensitive data, or further exploitation of the device's functionality.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA if sensitive data like WiFi credentials or recorded videos are exposed. Unauthorized access to personal or health-related information violates confidentiality requirements under these regulations.

Mitigation Strategies

Immediately isolate the Thinkware U3000 device from untrusted networks. Disable access to ports 7878 and 8787 if possible. Update the firmware to the latest version if an update is available. If no update exists, restrict network access to the device and monitor for unauthorized file access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101054. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart