Junglewise Threat Intelligence

CVE-2026-35904: T3 Technology CPE missing authentication in telnetenable.cgi

CVE-2026-35904 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: T3 Technology T625Pro, T3 Technology T6825G. Vendors: T3 Technology.

Executive brief

A security vulnerability exists in several T3 Technology home internet routers (CPE models). An unauthorized person on the same network can remotely enable the Telnet service, which is a tool used for administrative access. While this does not directly steal data, it opens a doorway for attackers to attempt further unauthorized access to the device's management systems.

Technical details

A missing authentication vulnerability (CWE-306) exists in the /cgi-bin/telnetenable.cgi component of T3 Technology CPE devices. The endpoint fails to validate sessions or authenticate requests; when called with the parameter 'telnetenable=1', the device adds an iptables/ebtables ACCEPT rule for TCP port 23 on the LAN bridge (br0) and launches the telnetd daemon. While the endpoint does not allow direct command execution, it significantly increases the attack surface by exposing the Telnet service to the local network. This can be exploited by an adjacent attacker via a direct GET request or by a remote attacker via a Blind Cross-Site Request Forgery (CSRF) attack.

Affected products

  • T3 Technology T625Pro v1.0.07
  • T3 Technology T6825G v1.0.03
  • T3 Technology T7281 v1.0.03
  • T3 Technology T628 Suspected affected due to shared codebase
  • T3 Technology T628L Suspected affected due to shared codebase

Timeline

  • 2026-06-04: disclosed: Initial advisory published by PwnOnu and MITRE

References

Related threats