Vulnerabilidad · Publicado 28/09/2026
Se identificó una vulnerabilidad (CVSS 7.3) en Thinkware U3000 versiones hasta 1.02.04 que afecta la función PUT_FILE en el archivo /tmp/wpa_supplicant.conf del servicio TCP. Un atacante remoto puede manipular parámetros de ruta para eludir controles de acceso. La vulnerabilidad ha sido divulgada públicamente y cuenta con exploits disponibles, aumentando el riesgo inmediato para organizaciones en LATAM que usan esta plataforma en dispositivos de conectividad empresarial.
A vulnerability was determined in Thinkware U3000 up to 1.02.04. This impacts the function PUT_FILE of the file /tmp/wpa_supplicant.conf of the component TCP Service. Executing a manipulation of the argument path can lead to improper access controls. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Score: 7.3/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE-266, CWE-284
Publicado en NIST NVD.