Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-6274 — Proof-of-concept exploit for CVE-2026-6274, an authentication bypass in Redline WR3200 routers allowing unauthorized password change via static cookie and missing IP check. | Kitploit
Tools/GitHubGitHub/bugresearch/cve-2026-6274
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingAuthentication
GitHubbugresearch/cve-2026-6274

CVE-2026-6274

Proof-of-concept exploit for CVE-2026-6274, an authentication bypass in Redline WR3200 routers allowing unauthorized password change via static cookie and missing IP check.

View Repository
134 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-6274: Redline WR3200 Authentication Bypass

English | Turkish

This repository contains the technical details and Proof of Concept (PoC) for CVE-2026-6274. The vulnerability exists in Redline WR3200 routers (prior to firmware v7.1.8) and allows an attacker to bypass authentication and change the administrative password without knowing the current credentials.

Technical Analysis

The vulnerability stems from two main security flaws:

  1. Static Cookie Authentication: The router relies on a static cookie (user=admin&platform=1) to identify administrative sessions.

  2. IP Verification Bypass: While most endpoints require an IP-based authorization, the password management endpoint (/goform/set_management_password) lacks this check, allowing unauthorized POST requests with the static cookie.

Usage

  1. Clone the repository:

    git clone https://github.com/bugresearch/CVE-2026-6274.git

    cd CVE-2026-6274

  2. Run the exploit:

    python3 exploit.py <target_ip> <new_pass>

Remediation

Users should upgrade their device firmware to v7.1.8

Download Tool