Share
## https://sploitus.com/exploit?id=D2A2BDA2-A827-5C81-ACD9-A68148EC42CC
# T3 Technology CPE โ€” Security Advisories

Multiple critical vulnerabilities discovered in T3 Technology CPE (ONU/Router) devices deployed by TrueOnline (Thailand).

## Vulnerabilities

| CVE ID | Severity | Summary |
|--------|----------|---------|
| [CVE-2026-35904](CVE-2026-35904.md) | **8.1 High** | Unauthenticated Telnet Enable via CGI |
| [CVE-2026-35905](CVE-2026-35905.md) | **8.8 High** | Hardcoded Root Credentials (`superadmin`) |
| [CVE-2026-35906](CVE-2026-35906.md) | **9.6 Critical** | Unauthenticated RCE via Debug CGI Endpoint |

## Kill Chain

These vulnerabilities can be chained for full device compromise:

```
CVE-2026-35906 (RCE as root)           โ† Critical: one-click root via browser
  โ”œโ”€โ”€ CVE-2026-35904 (Enable Telnet)   โ† Persistence: open management channel
  โ”œโ”€โ”€ CVE-2026-35905 (Hardcoded creds) โ† Login: same password on every device
  โ””โ”€โ”€ Full device compromise           โ† Game over
```

## Affected Devices

### Confirmed

| Model | Firmware |
|-------|----------|
| T625Pro (WiFi 6 AX3000) | V1.0.07 |
| T6825G (WiFi 6 AX5400) | V1.0.03 |
| T7281 (WiFi 7) | V1.0.03 |

### Suspected

| Model | Rationale |
|-------|-----------|
| T628 | Shared vendor SDK |
| T628L | Shared vendor SDK |

## Disclosure Timeline

| Date | Event |
|------|-------|
| 2026-02-10 | Reported to ThaiCERT/NCSA (national CERT) |
| 2026-02-10 | ThaiCERT/NCSA acknowledged receipt |
| 2026-04-29 | CVEs assigned by MITRE |
| 2026-05-11 | 90-day deadline expired โ€” no vendor response or patch |
| 2026-06-03 | Public disclosure |

> Disclosure follows the industry-standard 90-day responsible disclosure policy.  
> The vendor and national CERT were notified on 2026-02-10.  
> No response, patch, or mitigation was provided within the disclosure window.

## Disclaimer

All testing was performed on personally owned devices in a private lab environment. This research was conducted in good faith under responsible disclosure principles. No production networks or third-party devices were accessed.

## Author

**[pwnOnu](https://github.com/pwnOnu)** โ€” Independent Security Researcher