CVE-2026-6274: CWE-287 Improper Authentication in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200
Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Redline WR3200: from 7.1.3 before 7.1.8.
AI Analysis
Technical Summary
CVE-2026-6274 is an improper authentication vulnerability (CWE-287) in the Redline WR3200 device by DTS Electronics Industry and Trade Ltd. Co. It involves missing or weak authentication controls on critical functions, allowing unauthorized users to access functionality that should be protected by ACLs. This affects firmware versions starting at 7.1.3 and prior to 7.1.8. The vulnerability is rated critical with a CVSS 3.1 score of 9.8, reflecting its ease of exploitation over the network without privileges or user interaction and its severe impact on confidentiality, integrity, and availability. No official fix or mitigation has been published by the vendor as of the current data. The device is not a cloud service, so remediation depends on vendor patch releases.
Potential Impact
Successful exploitation of this vulnerability allows an unauthenticated attacker to access critical functions on the Redline WR3200 device that are not properly protected by authentication or ACLs. This can lead to complete compromise of the device's confidentiality, integrity, and availability, potentially allowing unauthorized control or disruption of device operations.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or remediation level is provided, users should monitor DTS Electronics Industry and Trade Ltd. Co. communications for updates. Until a patch is available, restrict network access to the affected devices to trusted sources only and consider additional network-level protections to limit exposure.
CVE-2026-6274: CWE-287 Improper Authentication in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200
Description
Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Redline WR3200: from 7.1.3 before 7.1.8.
CVSS v3.1
Score 9.8critical
Affected software
pkg:github/bugresearch/Redline-WR3200Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-6274 is an improper authentication vulnerability (CWE-287) in the Redline WR3200 device by DTS Electronics Industry and Trade Ltd. Co. It involves missing or weak authentication controls on critical functions, allowing unauthorized users to access functionality that should be protected by ACLs. This affects firmware versions starting at 7.1.3 and prior to 7.1.8. The vulnerability is rated critical with a CVSS 3.1 score of 9.8, reflecting its ease of exploitation over the network without privileges or user interaction and its severe impact on confidentiality, integrity, and availability. No official fix or mitigation has been published by the vendor as of the current data. The device is not a cloud service, so remediation depends on vendor patch releases.
Potential Impact
Successful exploitation of this vulnerability allows an unauthenticated attacker to access critical functions on the Redline WR3200 device that are not properly protected by authentication or ACLs. This can lead to complete compromise of the device's confidentiality, integrity, and availability, potentially allowing unauthorized control or disruption of device operations.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or remediation level is provided, users should monitor DTS Electronics Industry and Trade Ltd. Co. communications for updates. Until a patch is available, restrict network access to the affected devices to trusted sources only and consider additional network-level protections to limit exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- TR-CERT
- Date Reserved
- 2026-04-14T13:36:24.251Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a22946de29bf47b50525696
Added to database: 06/05/2026, 09:18:37 UTC
Last enriched: 06/12/2026, 09:53:38 UTC
Last updated: 07/21/2026, 20:57:08 UTC
Views: 104
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.