Think Router Tk-Rt-Wr135G Authentication Bypass Vulnerability via Crafted Cookie

Vulnerability

An authentication bypass vulnerability has been identified in the Think Router model Tk-Rt-Wr135G, specifically in firmware version 3.0.2-X000. This vulnerability allows attackers to bypass the login form by manipulating the LoginStatus cookie. By changing the cookie's value from 'false' to 'true', an attacker can gain unauthorized access to the router's configuration settings. The exploitation of this vulnerability could lead to various attacks, such as DNS hijacking, unauthorized firmware updates, or sending unauthenticated requests to the router using tools like curl.

Impact

Exploitation of this vulnerability could allow for unauthorized access to the router's configuration, potentially leading to DNS hijacking, unauthorized firmware updates, or other malicious actions via unauthenticated requests to the router.

Reproduction

The vulnerability can be reproduced by using a web browser's console or a cookie inspector to modify the LoginStatus cookie. Changing the cookie's value from 'false' to 'true' will bypass the authentication process, allowing access to the router's settings.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.