
CVE-2026-35904 / CVE-2026-35905 / CVE-2026-35906 — Unauth RCE, Hardcoded Root Creds & Telnet Enable in T3 Technology CPE
Multiple critical vulnerabilities discovered in T3 Technology CPE (ONU/Router) devices deployed by TrueOnline (Thailand).
| CVE ID | Severity | Summary |
|---|---|---|
| CVE-2026-35904 | 4.3 Medium | Unauthenticated Telnet Enable via CGI |
| CVE-2026-35905 | 8.8 High | Hardcoded Root Credentials (superadmin) |
| CVE-2026-35906 | 9.6 Critical | Unauthenticated RCE via Debug CGI Endpoint |
Note on scoring: CVE-2026-35904 is scored on its isolated impact per CVSS v3.1 §3.5 — enabling the Telnet service is a configuration-integrity change (Medium). Its role in full device compromise comes only when chained with CVE-2026-35905 / CVE-2026-35906, as shown below.
These vulnerabilities can be chained for full device compromise:
CVE-2026-35906 (RCE as root) ← Critical: one-click root via browser
├── CVE-2026-35904 (Enable Telnet) ← Persistence: open management channel
├── CVE-2026-35905 (Hardcoded creds) ← Login: same password on every device
└── Full device compromise ← Game over
| Model | Firmware |
|---|---|
| T625Pro (WiFi 6 AX3000) | V1.0.07 |
| T6825G (WiFi 6 AX5400) | V1.0.03 |
| T7281 (WiFi 7) | V1.0.03 |
| Model | Rationale |
|---|---|
| T628 | Shared vendor SDK |
| T628L | Shared vendor SDK |
| Date | Event |
|---|---|
| 2026-02-10 | Reported to ThaiCERT/NCSA (national CERT) |
| 2026-02-10 | ThaiCERT/NCSA acknowledged receipt |
| 2026-04-29 | CVEs assigned by MITRE |
| 2026-05-11 | 90-day deadline expired — no vendor response or patch |
| 2026-06-03 | Public disclosure |
Disclosure follows the industry-standard 90-day responsible disclosure policy. The vendor and national CERT were notified on 2026-02-10. No response, patch, or mitigation was provided within the disclosure window.
All testing was performed on personally owned devices in a private lab environment. This research was conducted in good faith under responsible disclosure principles. No production networks or third-party devices were accessed.
pwnOnu — Independent Security Researcher