Description
T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded password for root access under the "superadmin" account.
Published: 2026-06-04
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a hardcoded password for the superadmin account on specific T3 Technology CPE models. An attacker who can reach the device can authenticate as root and gain unrestricted access, allowing configuration changes, data exfiltration, or further exploitation of the system.

Affected Systems

Affected models are T3 Technology T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03.

Risk and Exploitability

No EPSS information and the vulnerability is not listed in CISA KEV, but the presence of a hardcoded password means that the attack path is trivial once connectivity is available. The problem is purely credential-based and does not rely on any complex code execution. The risk level is high because the attacker can perform any privileged action on the device, and patching or changing the credential is the only effective mitigation.

Generated by OpenCVE AI on June 4, 2026 at 15:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to a version that removes the hardcoded superadmin password.
  • If no firmware update is available, disable or rename the superadmin account and set a strong unique password for any administrative accounts.
  • Restrict network access to the device using firewall rules or VLAN segmentation so that only trusted management hosts can reach it.
  • Enable and monitor audit logs to detect unauthorized login attempts.

Generated by OpenCVE AI on June 4, 2026 at 15:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 04 Jun 2026 15:45:00 +0000

Type Values Removed Values Added
Title Hardcoded Root Password in T3 Technology CPE Devices
Weaknesses CWE-798

Thu, 04 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Description T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded password for root access under the "superadmin" account.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-04T13:54:55.387Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-35905

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-04T15:16:50.707

Modified: 2026-06-04T15:16:50.707

Link: CVE-2026-35905

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-04T15:30:17Z

Weaknesses