Sceawere
Vulnerability Detail
CVE-2026-101055UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Thinkware U3000 Information Disclosure Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 3h ago
- Vendor
- Thinkware
- Product
- U3000
- Attack Type
- Information Disclosure
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A security flaw has been discovered in Thinkware U3000 up to 1.02.04. Affected by this vulnerability is the function GET_STATUS of the component TCP Service. The manipulation of the argument wifi_info results in information disclosure. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-09-28T13:17:19.677Z",
"pubdate": "2026-09-28T13:17:19.677Z",
"executiveSummary": "A critical information disclosure vulnerability exists in the Thinkware U3000 dashcam, affecting firmware versions up to 1.02.04.\nThe vulnerability resides within the TCP Service, specifically targeting the GET_STATUS function, which fails to properly validate the wifi_info argument.\nThis flaw allows remote, unauthenticated attackers to query the device and retrieve sensitive system information.\nThe risk is elevated due to the public availability of exploit code, which may facilitate unauthorized access or reconnaissance against affected devices.\nThe vendor has remained unresponsive to disclosure attempts, leaving the devices unpatched and susceptible to exploitation in their current state.\nSuccessful exploitation compromises the confidentiality of the device's wireless configuration and potentially other internal system states exposed by the vulnerable function.",
"technicalDetails": "The vulnerability is an Improper Input Validation flaw located within the TCP Service component of the Thinkware U3000 firmware.\nSpecifically, the GET_STATUS function processes requests from the TCP interface but does not adequately sanitize or restrict the input provided via the wifi_info argument.\nThe attack flow involves an adversary establishing a remote connection to the device's TCP service port. Once the session is initiated, the attacker sends a crafted request packet invoking the GET_STATUS function.\nBy manipulating the wifi_info argument within this payload, an attacker can bypass intended access controls, forcing the service to return information that should otherwise be protected or restricted.\nThe root cause is a failure in the application logic to perform bounds checking or validation on the input parameter before processing it within the function logic, leading to an unauthorized disclosure of system state information.\nBecause the TCP service is exposed for remote access, no physical interaction with the device is required to trigger this vulnerability.\nThe lack of authentication requirements for the TCP service makes this an especially low-barrier attack, as any network-adjacent entity can execute the exploit code to harvest data from the device.\nPost-exploitation, an attacker can gain insight into the wireless environment, including details about the current Wi-Fi configuration, potentially exposing credentials or network topology information that could be leveraged for further attacks or lateral movement within a local network.\nThe vulnerability is confirmed in versions up to 1.02.04, and given the nature of the TCP service implementation, the disclosure occurs in plaintext or clear-text responses, significantly lowering the complexity for an attacker to parse the exfiltrated data."
}