Thinkware · U3000 · CVE-2026-101053
**Name of the Vulnerable Software and Affected Versions**
Thinkware U3000 versions prior to 1.02.04
**Description**
An issue exists in the TCP Service component where manipulating the `path` argument within the `PUT FILE()` function for the file `/tmp/wpa supplicant.conf` can lead to improper access controls. This flaw allows a remote attacker to bypass security restrictions.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary mitigation, restrict remote access to the TCP Service component.