Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in Thinkware U3000 up to 1.02.04. This impacts the function PUT_FILE of the file /tmp/wpa_supplicant.conf of the component TCP Service. Executing a manipulation of the argument path can lead to improper access controls. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Thinkware U3000 TCP Service wpa_supplicant.conf PUT_FILE access control | |
| First Time appeared |
Thinkware
Thinkware u3000 |
|
| Weaknesses | CWE-266 CWE-284 |
|
| CPEs | cpe:2.3:a:thinkware:u3000:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Thinkware
Thinkware u3000 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-28T12:46:30.387Z
Reserved: 2026-09-27T16:26:26.231Z
Link: CVE-2026-101053
Updated: 2026-09-28T12:46:23.315Z
Status : Deferred
Published: 2026-09-28T12:17:36.230
Modified: 2026-09-28T15:16:04.793
Link: CVE-2026-101053
No data.
OpenCVE Enrichment
Updated: 2026-09-28T16:22:41Z