Description
A security flaw has been discovered in Thinkware U3000 up to 1.02.04. Affected by this vulnerability is the function GET_STATUS of the component TCP Service. The manipulation of the argument wifi_info results in information disclosure. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the GET_STATUS function of the TCP Service on Thinkware U3000 cameras. By manipulating the wifi_info argument, a remote attacker can retrieve sensitive information disclosed by the device. This flaw leads to an information exposure (CWE‑200) and also raises concerns over improper authorization controls (CWE‑284). The disclosed data could include Wi-Fi credentials and other configuration details, potentially enabling further compromise of the network.

Affected Systems

Thinkware U3000 cameras running firmware versions up to and including 1.02.04 are affected. Vendors and product names identified by CNA are Thinkware:U3000. No other products or versions are listed as impacted.

Risk and Exploitability

The CVSS base score of 6.9 denotes a moderate impact. Although EPSS is not available, the public release of the exploit and the ability to execute the attack remotely suggest a realistic exploitation window. The flaw is not listed in CISA KEV, but the lack of vendor response and the publicly available code mean attackers can craft and deploy an exploit at their convenience. The risk is therefore moderate to high, especially for devices exposed to the Internet.

Generated by OpenCVE AI on September 28, 2026 at 13:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the camera firmware to a version later than 1.02.04 where the GET_STATUS function is patched.
  • If a firmware update is unavailable, block the TCP service port that handles GET_STATUS requests using a network firewall or router rule to prevent external access.
  • Apply network segmentation and isolate the camera from critical internal networks to limit the impact of any potential credential disclosure.

Generated by OpenCVE AI on September 28, 2026 at 13:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Thinkware U3000 up to 1.02.04. Affected by this vulnerability is the function GET_STATUS of the component TCP Service. The manipulation of the argument wifi_info results in information disclosure. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title Thinkware U3000 TCP Service GET_STATUS information disclosure
First Time appeared Thinkware
Thinkware u3000
Weaknesses CWE-200
CWE-284
CPEs cpe:2.3:a:thinkware:u3000:*:*:*:*:*:*:*:*
Vendors & Products Thinkware
Thinkware u3000
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T13:24:09.474Z

Reserved: 2026-09-27T16:28:18.076Z

Link: CVE-2026-101055

cve-icon Vulnrichment

Updated: 2026-09-28T13:23:41.106Z

cve-icon NVD

Status : Deferred

Published: 2026-09-28T13:17:19.677

Modified: 2026-09-28T15:16:04.793

Link: CVE-2026-101055

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T13:30:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control