
Proof-of-concept exploit for CVE-2026-6274, an authentication bypass in Redline WR3200 routers allowing unauthorized password change via static cookie and missing IP check.
This repository contains the technical details and Proof of Concept (PoC) for CVE-2026-6274. The vulnerability exists in Redline WR3200 routers (prior to firmware v7.1.8) and allows an attacker to bypass authentication and change the administrative password without knowing the current credentials.
The vulnerability stems from two main security flaws:
Static Cookie Authentication: The router relies on a static cookie (user=admin&platform=1) to identify administrative sessions.
IP Verification Bypass: While most endpoints require an IP-based authorization, the password management endpoint (/goform/set_management_password) lacks this check, allowing unauthorized POST requests with the static cookie.
Clone the repository:
git clone https://github.com/bugresearch/CVE-2026-6274.git
cd CVE-2026-6274
Run the exploit:
python3 exploit.py <target_ip> <new_pass>
Users should upgrade their device firmware to v7.1.8