CVE-2026-101055
Thinkware U3000 TCP Service GET_STATUS information disclosure
- Published
- Sep 28, 2026
- Updated
- Sep 28, 2026
- Assigning CNA
- VulDB
- Evidence observed
- Oct 3, 2026
Thinkware U3000 TCP Service GET_STATUS information disclosure
nvd · CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XA security flaw has been discovered in Thinkware U3000 up to 1.02.04. Affected by this vulnerability is the function GET_STATUS of the component TCP Service. The manipulation of the argument wifi_info results in information disclosure. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Three unauthenticated vulnerabilities in the Thinkware U3000 dashcam's local WiFi control protocol: arbitrary file write, arbitrary file read, and plaintext WiFi credential disclosure. CVE-2026-101053, CVE-2026-101054, CVE-2026-101055.
Python client for the Thinkware U3000 dashcam's local WiFi control protocol, reverse-engineered from the official Android app. PoC tooling behind CVE-2026-101053, CVE-2026-101054, and CVE-2026-101055.
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.