Share
## https://sploitus.com/exploit?id=D2A2BDA2-A827-5C81-ACD9-A68148EC42CC
# T3 Technology CPE โ Security Advisories
Multiple critical vulnerabilities discovered in T3 Technology CPE (ONU/Router) devices deployed by TrueOnline (Thailand).
## Vulnerabilities
| CVE ID | Severity | Summary |
|--------|----------|---------|
| [CVE-2026-35904](CVE-2026-35904.md) | **8.1 High** | Unauthenticated Telnet Enable via CGI |
| [CVE-2026-35905](CVE-2026-35905.md) | **8.8 High** | Hardcoded Root Credentials (`superadmin`) |
| [CVE-2026-35906](CVE-2026-35906.md) | **9.6 Critical** | Unauthenticated RCE via Debug CGI Endpoint |
## Kill Chain
These vulnerabilities can be chained for full device compromise:
```
CVE-2026-35906 (RCE as root) โ Critical: one-click root via browser
โโโ CVE-2026-35904 (Enable Telnet) โ Persistence: open management channel
โโโ CVE-2026-35905 (Hardcoded creds) โ Login: same password on every device
โโโ Full device compromise โ Game over
```
## Affected Devices
### Confirmed
| Model | Firmware |
|-------|----------|
| T625Pro (WiFi 6 AX3000) | V1.0.07 |
| T6825G (WiFi 6 AX5400) | V1.0.03 |
| T7281 (WiFi 7) | V1.0.03 |
### Suspected
| Model | Rationale |
|-------|-----------|
| T628 | Shared vendor SDK |
| T628L | Shared vendor SDK |
## Disclosure Timeline
| Date | Event |
|------|-------|
| 2026-02-10 | Reported to ThaiCERT/NCSA (national CERT) |
| 2026-02-10 | ThaiCERT/NCSA acknowledged receipt |
| 2026-04-29 | CVEs assigned by MITRE |
| 2026-05-11 | 90-day deadline expired โ no vendor response or patch |
| 2026-06-03 | Public disclosure |
> Disclosure follows the industry-standard 90-day responsible disclosure policy.
> The vendor and national CERT were notified on 2026-02-10.
> No response, patch, or mitigation was provided within the disclosure window.
## Disclaimer
All testing was performed on personally owned devices in a private lab environment. This research was conducted in good faith under responsible disclosure principles. No production networks or third-party devices were accessed.
## Author
**[pwnOnu](https://github.com/pwnOnu)** โ Independent Security Researcher