Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/pwnonu/t3-technology-cpe-advisories
Embedded Systems SecurityIoT SecurityVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingHardware SecurityRed Teaming
GitHubpwnonu/t3-technology-cpe-advisories

T3-Technology-CPE-Advisories

CVE-2026-35904 / CVE-2026-35905 / CVE-2026-35906 — Unauth RCE, Hardcoded Root Creds & Telnet Enable in T3 Technology CPE

View Repository
173 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

T3 Technology CPE — Security Advisories

Multiple critical vulnerabilities discovered in T3 Technology CPE (ONU/Router) devices deployed by TrueOnline (Thailand).

Vulnerabilities

CVE IDSeveritySummary
CVE-2026-359044.3 MediumUnauthenticated Telnet Enable via CGI
CVE-2026-359058.8 HighHardcoded Root Credentials (superadmin)
CVE-2026-359069.6 CriticalUnauthenticated RCE via Debug CGI Endpoint

Note on scoring: CVE-2026-35904 is scored on its isolated impact per CVSS v3.1 §3.5 — enabling the Telnet service is a configuration-integrity change (Medium). Its role in full device compromise comes only when chained with CVE-2026-35905 / CVE-2026-35906, as shown below.

Kill Chain

These vulnerabilities can be chained for full device compromise:

CVE-2026-35906 (RCE as root)           ← Critical: one-click root via browser
  ├── CVE-2026-35904 (Enable Telnet)   ← Persistence: open management channel
  ├── CVE-2026-35905 (Hardcoded creds) ← Login: same password on every device
  └── Full device compromise           ← Game over

Affected Devices

Confirmed

ModelFirmware
T625Pro (WiFi 6 AX3000)V1.0.07
T6825G (WiFi 6 AX5400)V1.0.03
T7281 (WiFi 7)V1.0.03

Suspected

ModelRationale
T628Shared vendor SDK
T628LShared vendor SDK

Disclosure Timeline

DateEvent
2026-02-10Reported to ThaiCERT/NCSA (national CERT)
2026-02-10ThaiCERT/NCSA acknowledged receipt
2026-04-29CVEs assigned by MITRE
2026-05-1190-day deadline expired — no vendor response or patch
2026-06-03Public disclosure

Disclosure follows the industry-standard 90-day responsible disclosure policy. The vendor and national CERT were notified on 2026-02-10. No response, patch, or mitigation was provided within the disclosure window.

Disclaimer

All testing was performed on personally owned devices in a private lab environment. This research was conducted in good faith under responsible disclosure principles. No production networks or third-party devices were accessed.

Author

pwnOnu — Independent Security Researcher

Download Tool