Junglewise Threat Intelligence

CVE-2026-35905: T3 Technology CPE hardcoded root password in superadmin account

CVE-2026-35905 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: T3 Technology T625Pro, T3 Technology T6825G. Vendors: T3 Technology.

Executive brief

Multiple T3 Technology home internet routers (CPE) contain a permanent, unchangeable administrative password. This allows anyone with access to the local network to log in as a 'superadmin' with full control over the device. An attacker could use this access to monitor internet traffic, change network settings, or disable the device entirely.

Technical details

A hardcoded credentials vulnerability (CWE-798) exists in the firmware of T3 Technology CPE models T625Pro (v1.0.07), T6825G (v1.0.03), and T7281 (v1.0.03). The 'superadmin' account uses a static password ('t4246#5753') that is identical across all units and cannot be modified by the user. This account provides root-level access via Telnet and the web management interface. An attacker on the adjacent network (e.g., local Wi-Fi or LAN) can exploit this to gain complete administrative control of the device. The vulnerability is suspected to affect other models using the same SDK, such as the T628 and T628L.

Affected products

  • T3 Technology T625Pro v1.0.07
  • T3 Technology T6825G v1.0.03
  • T3 Technology T7281 v1.0.03

Timeline

  • 2026-06-04: disclosed: Initial disclosure via GitHub and NVD

References

Related threats