CVE-2026-35904

CRITICAL

T3 Technology CPE T625Pro 1.0.07 T6825G 1.0.03 T7281 1.0.03 - Unauthenticated Telnet Service Enablement via CGI Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-35904. PoCs published by PwnOnu.

AI-analyzed exploit summary This repository contains detailed technical writeups for three CVEs affecting T3 Technology CPE devices, including CVE-2026-35904 (unauthenticated Telnet enable), CVE-2026-35905 (hardcoded root credentials), and CVE-2026-35906 (unauthenticated RCE via debug CGI endpoint). The writeups include vulnerability details, proof-of-concept examples, attack scenarios, and remediation guidance.

Description

Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 allows unauthorized attackers to enable the Telnet service via sending a crafted request to a vulnerable CGI component.

Exploits (1)

nomisec WRITEUP
by PwnOnu · poc
https://github.com/PwnOnu/T3-Technology-CPE-Advisories

This repository contains detailed technical writeups for three CVEs affecting T3 Technology CPE devices, including CVE-2026-35904 (unauthenticated Telnet enable), CVE-2026-35905 (hardcoded root credentials), and CVE-2026-35906 (unauthenticated RCE via debug CGI endpoint). The writeups include vulnerability details, proof-of-concept examples, attack scenarios, and remediation guidance.

Classification
Writeup 100%
Attack Type
Auth Bypass | Rce | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: T3 Technology CPE devices (T625Pro, T6825G, T7281, etc.)
No auth needed
Prerequisites: Network access to the target device
devstral-2 · analyzed Jun 05, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0005
EPSS Percentile 17.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-284
Status published
Published Jun 04, 2026
Tracked Since Jun 04, 2026