Impact
The vulnerability resides in the GET_STATUS function of the TCP Service on Thinkware U3000 cameras. By manipulating the wifi_info argument, a remote attacker can retrieve sensitive information disclosed by the device. This flaw leads to an information exposure (CWE‑200) and also raises concerns over improper authorization controls (CWE‑284). The disclosed data could include Wi-Fi credentials and other configuration details, potentially enabling further compromise of the network.
Affected Systems
Thinkware U3000 cameras running firmware versions up to and including 1.02.04 are affected. Vendors and product names identified by CNA are Thinkware:U3000. No other products or versions are listed as impacted.
Risk and Exploitability
The CVSS base score of 6.9 denotes a moderate impact. Although EPSS is not available, the public release of the exploit and the ability to execute the attack remotely suggest a realistic exploitation window. The flaw is not listed in CISA KEV, but the lack of vendor response and the publicly available code mean attackers can craft and deploy an exploit at their convenience. The risk is therefore moderate to high, especially for devices exposed to the Internet.
OpenCVE Enrichment