天下漏洞,尽知其名
HIGH

CVE-2026-101053 Thinkware U3000 访问控制漏洞

影响远程攻击者可越权写入文件,可能篡改设备配置

AI 研判

Thinkware U3000 行车记录仪(版本至 1.02.04)的 TCP 服务中,PUT_FILE 功能处理 path 参数时存在访问控制不当问题。攻击者可远程利用该缺陷操作 /tmp/wpa_supplicant.conf 文件,且利用代码已公开。厂商已被告知但未作回应。

影响范围

Thinkware U3000

Thinkware U3000 至 1.02.04 版本受影响,更高版本是否修复暂无公开信息。

漏洞详情

漏洞属于访问控制不当(越权文件操作)类型。TCP 服务的 PUT_FILE 功能未对传入的 path 参数做充分校验,导致攻击者可指定任意路径写入或覆盖文件,例如 /tmp/wpa_supplicant.conf。该缺陷可被远程触发,且公开的利用方式可能已被实际使用。

利用条件与风险

攻击者需能通过网络访问设备的 TCP 服务端口,无需认证即可尝试利用。由于利用代码已公开且厂商未回应,实战中被扫描和攻击的风险较高。

修复建议

官方暂未发布修复方案,建议关注厂商公告。临时缓解措施包括限制 TCP 服务端口的网络暴露、仅允许可信网络访问,或停用相关服务。

原始情报

A vulnerability was determined in Thinkware U3000 up to 1.02.04. This impacts the function PUT_FILE of the file /tmp/wpa_supplicant.conf of the component TCP Service. Executing a manipulation of the argument path can lead to improper access controls. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.