CVE-2026-6274 affects DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 versions 7.1.3 through before 7.1.8. The issue is described as a combination of improper authentication, missing authentication for a critical function, and weak authentication that allows access to functionality not properly constrained by ACLs. Based on the available information, exposed device functionality can be reached over the network without proper authentication enforcement, enabling unauthorized access to privileged or restricted operations. The published record maps the issue to CWE-287, CWE-306, and CWE-1390, indicating authentication design and enforcement weaknesses rather than a memory-safety flaw.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Small standalone exploit repository containing one Python PoC script and two README files (English and Turkish). The exploit targets CVE-2026-6274 in Redline WR3200 routers before firmware v7.1.8. The core issue described by the repository is an authentication bypass caused by reliance on static cookies (user=admin and platform=1) combined with insufficient authorization checks on the password-management endpoint. The Python script exploit.py is the only code file and main entry point. It accepts a target IP and a new password, builds an HTTP POST request to /goform/set_manpwd, sets the static cookies, and includes browser-like headers such as X-Requested-With, Content-Type, Referer, and User-Agent. If the target responds with HTTP 200, the script reports success and prints the server response. The exploit does not provide shell access or code execution; its capability is limited but impactful: unauthorized administrative password reset on the router. This is a real exploit PoC rather than a detector, with a hardcoded attack flow and no framework integration.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.