Junglewise Threat Intelligence

CVE-2026-6274: DTS Redline WR3200 authentication bypass in administrative functions

CVE-2026-6274 · Severity: critical · CVSS 9.8 · Published 2026-06-05

Executive brief

The Redline WR3200 router, a networking device used for internet connectivity, contains a critical security flaw where administrative functions are not properly protected. This allows unauthorized individuals to bypass login requirements and gain full control over the device remotely. An attacker could potentially intercept network traffic, modify device settings, or disable the internet connection entirely.

Technical details

This vulnerability encompasses Improper Authentication (CWE-287), Missing Authentication for Critical Function (CWE-306), and Weak Authentication (CWE-1390) within the Redline WR3200 router firmware. The flaw allows a remote, unauthenticated attacker to bypass Access Control Lists (ACLs) and execute administrative functions. The attack vector is network-based with low complexity and requires no user interaction or prior privileges. Successful exploitation grants the attacker the ability to view sensitive data, modify configurations, or cause a denial of service. The issue is addressed in firmware version 7.1.8.

Affected products

  • DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 7.1.3 to 7.1.7

Timeline

  • 2026-06-05: advisory: Initial disclosure by TR-CERT and NVD

References