Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/turretsec/u3000py
Embedded Systems SecurityIoT SecurityVulnerability AnalysisExploitationReverse EngineeringInformation GatheringNetwork SecurityUtilities & FrameworksHardware & IoT SecurityPapers & Research
GitHubturretsec/u3000py

u3000py

Python client for the Thinkware U3000 dashcam's local WiFi control protocol, reverse-engineered from the official Android app. PoC tooling behind CVE-2026-101053, CVE-2026-101054, and CVE-2026-101055.

View Repository
5 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

u3000py

A Python client for the Thinkware U3000 dashcam's local WiFi control protocol, reverse-engineered from the official Android app, confirmed against real hardware, not from any public spec (there isn't one).

This project has two purposes: a usable library for pulling footage off your own dashcam, and supporting material for a completed CVE disclosure (see Security below).

Before you use this

  • The camera's control protocol has no authentication and no encryption. Anyone on the same network as the camera can issue any command this library can.
  • Every behavior in this library is either confirmed against real hardware or explicitly flagged as unverified in its docstring. See docs/protocol-reference.md for the full breakdown of what's solid and what's a guess.
  • A handful of methods are gated behind confirm=True because they're destructive (formatting the SD card) or because they can disconnect the camera from the network you're using to reach it (set_wifi_mode, connect_to_ap, etc.). Read the docstring before passing confirm=True on any of these.

Install

No PyPI release. Install straight from GitHub:

pip install "u3000py[cli] @ git+https://github.com/turretsec/u3000py.git"

Or without the CLI, just the library:

pip install git+https://github.com/turretsec/u3000py.git

Or pin to a tagged release:

pip install git+https://github.com/turretsec/[email protected]

Quick start

from u3000py import ThinkLinkClient, VideoCategory

with ThinkLinkClient("192.168.1.100") as cam:  # your camera's actual IP
    print(cam.get_device_info())
    print(cam.get_system_status())

    files = cam.list_files(VideoCategory.CONTINUOUS)
    latest = files[-1]

    def show_progress(received, total):
        print(f"\r{received / total:.0%}", end="")

    cam.download(latest.path, dest="latest_clip.mp4", progress=show_progress)

Or from the command line, once installed with the [cli] extra:

u3000py --host 192.168.1.100 info device
u3000py --host 192.168.1.100 files download --latest --category cont_rec

--host is required on every invocation, either as the flag shown above or via the U3000PY_HOST environment variable if you'd rather not repeat it.

What it can do

  • Status: device info, system status, free space, GPS, WiFi credentials (yes, the camera will hand these back to anyone who asks, see Security), live telemetry, hotspot count
  • Files: browse any directory, list/categorize recordings, download with progress, generate thumbnails
  • Camera config: switch preview channel, toggle audio recording, reset GPS/ADAS, factory reset, format SD card
  • WiFi/hotspot management: connect to networks, manage saved access points, manage the camera's own hotspot, switch WiFi mode
  • Diagnostics: parking event data, state history, modem info (this unit appears to have none)

Full method-by-method detail, including which results came from real hardware tests vs. which are educated guesses pending verification, lives in the protocol reference doc.

What's deliberately not here

  • PUT_FILE: confirmed to allow unauthenticated arbitrary file writes to any absolute path on the camera's filesystem. This is one of three CVE findings; shipping a generic write-anywhere method in a public library would hand out a ready-to-use attack tool. Full detail in disclosure-thinkware-u3000.
  • Firmware flashing: not a security call, a "please don't brick your own dashcam" call. No signature verification or vendor validation happens at this layer.
  • A keepalive/auto-sync daemon: the camera's WiFi connection appears to need either the official app open or a periodic heartbeat to stay reachable. Real, useful feature, deliberately out of scope for this repo, planned as a separate project.
  • Anything that behaves like a generic remote shell: every method here maps to one specific, named camera operation. Nothing here is a parameterized "run an arbitrary command" primitive.

Testing

pip install -e ".[dev]"
pytest -v                                  # unit tests, no camera needed
pytest -m hardware --host 192.168.1.100    # real-camera tests, opt-in only

A standalone smoke-test script for the CLI itself lives in scripts/smoke_test_cli.py. It's not part of the pytest suite (it shells out to the real installed u3000py command against a real camera) for sanity checks after changes.

Documentation

  • docs/protocol-reference.md: the full reverse-engineered protocol; wire format, every confirmed command, what's still unverified, and known open mysteries (a couple of things genuinely don't behave the way the protocol's own conventions would predict).

Security

This protocol has no authentication. Three findings came out of this research, fully documented and disclosed in a separate repository: disclosure-thinkware-u3000.

  1. Unauthenticated arbitrary file write via PUT_FILE (CVE-2026-101053 (VulDB #410915)), confirmed by writing into the camera's real /tmp directory. Deliberately not exposed by this library (see What's deliberately not here above).
  2. Unauthenticated arbitrary file read via LS/GET_FILE (CVE-2026-101054 (VulDB #410916)), no path restriction at all. This library's download() method demonstrates the primitive directly, e.g. cam.download("/tmp/wpa_supplicant.conf") reads the device's live WiFi configuration file.
  3. Plaintext WiFi credential disclosure via GET_STATUS "wifi_info" (CVE-2026-101055 (VulDB #410917)). This library's get_wifi_info() demonstrates the primitive directly (with the password redacted by default in any printed output, see WifiInfo's repr()).

Thinkware was notified on 2026-06-21. The 30-day disclosure window closed on 2026-07-21 with only a non-technical acknowledgment of receipt and no fix confirmation. All three findings remain reproducible on the current production firmware. Related prior research on a different Thinkware model (F800 Pro) by geo-chen is referenced in the disclosure repo for context.

License

MIT, see LICENSE.

Download Tool