Description
Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Redline WR3200: from 7.1.3 before 7.1.8.
Published: 2026-06-05
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper authentication allows an attacker to bypass normal login controls and access critical functions that are not correctly protected by access‑control lists. The weakness lies in missing or weak authentication mechanisms for sensitive operations. An attacker who can reach the device may remotely execute privileged actions, potentially altering configuration, disrupting service, or escalating privileges. Because the bug is rooted in missing authentication, any user with network access can exploit it, making the risk far‑flung across all unpatched units.

Affected Systems

Vendors impacted are DTS Electronics Industry and Trade Ltd. Co. The Redline WR3200 router is compromised for firmware revisions starting with 7.1.3 up to but excluding 7.1.8. Devices running those firmware images lack the authentication control required for certain functions and are therefore exploitable.

Risk and Exploitability

With a CVSS score of 9.8 the vulnerability is considered critical, granting an attacker full control over the device’s configuration and services. The EPSS score is currently unavailable, so the likelihood of exploitation is unknown, but the lack of any mitigations or conditional restrictions in the firmware means remote attackers can reach the device and exercise the bypass freely. The vulnerability is not yet identified in CISA’s KEV listing, yet its high severity warrants immediate attention. Because the flaw sits in the authorization layer, it can be exploited over the network using the device’s management protocols without requiring elevated privileges.

Generated by OpenCVE AI on June 5, 2026 at 10:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Redline WR3200 firmware to version 7.1.8 or later, which removes the authentication bypass flaw.
  • Temporarily block external management interfaces on the router (e.g., restrict access to the device to a trusted internal network or isolate using a firewall).
  • Enforce strict access controls by configuring ACLs on the device to allow only known IP addresses or users to connect to management ports, ensuring that all privileged functions remain protected.

Generated by OpenCVE AI on June 5, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 05 Jun 2026 09:15:00 +0000

Type Values Removed Values Added
Description Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Redline WR3200: from 7.1.3 before 7.1.8.
Title Authentication Bypass in DTS Electronics' Redline WR3200
Weaknesses CWE-1390
CWE-287
CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-06-05T20:21:36.106Z

Reserved: 2026-04-14T13:36:24.251Z

Link: CVE-2026-6274

cve-icon Vulnrichment

Updated: 2026-06-05T20:21:31.756Z

cve-icon NVD

Status : Deferred

Published: 2026-06-05T09:16:26.373

Modified: 2026-06-05T15:56:47.570

Link: CVE-2026-6274

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T10:30:27Z

Weaknesses