Executive brief
A security vulnerability exists in certain T3 Technology home routers and network equipment. An undocumented maintenance tool left in the device's software allows unauthorized individuals to take complete control of the router over the internet. This could lead to the theft of personal data, monitoring of internet traffic, or the use of the device in larger cyberattacks.
Technical details
The vulnerability stems from an undocumented debug CGI endpoint present in the firmware of T3 Technology CPE models T625Pro (v1.0.07) and T6825G (v1.0.03). An unauthenticated attacker can exploit this by sending a specially crafted HTTP query string to the vulnerable endpoint. This results in arbitrary command execution with root privileges on the underlying operating system. The attack is reachable over the network without any prior authentication or user interaction. At the time of reporting, users are advised to check for firmware updates from their service providers.
Affected products
- T3 Technology T625Pro v1.0.07
- T3 Technology T6825G v1.0.03
Timeline
- 2026-06-04: disclosed: Initial disclosure of CVE-2026-35906
- 2026-06-04: advisory: NVD publication date