Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-55211 — Cookie-based authentication vulnerability on Tk-Rt-Wr135G | Kitploit
Tools/GitHubGitHub/micaelmaciel/cve-2024-55211
Authentication & AuthorizationIoT SecurityExploitationWeb Application ExploitationDNS AnalysisFirmware Analysis
GitHubmicaelmaciel/cve-2024-55211

CVE-2024-55211

Cookie-based authentication vulnerability on Tk-Rt-Wr135G

View Repository
210 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-55211

Cookie-based authentication vulnerability on Tk-Rt-Wr135G

Affected vendor: Think Technology

Affected product: Wireless Router Ac 1199Mbps Tk-Rt-Wr135G

Affected version: Firmware V3.0.2-X000

Description

The vulnerability allows the bypass of the login form in the router TK-RT-WR135G, allowing the attacker to change any configuration designed for the router. This is made possible by changing the value of the LoginStatus cookie, altering its initial value of "false" to "true", which makes the user logged in for a set period of time.

Exploit

It can be exploited via a web browser's console or a cookie inspector.

Attack vectors

The vulnerability allows for attack vectors such as DNS hijacking by altering the default DNS to any arbitrary one hosted on a machine that's part of the LAN with custom DNS rules, custom firmware updates and direct un-authed requests to the router using tools such as curl.

PoC

https://github.com/user-attachments/assets/e7c26afc-85f3-4f0e-be34-63df5e3084ca

Download Tool