Description
T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded password for root access under the "superadmin" account.
Published: 2026-06-04
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a hardcoded password for the superadmin account on specific T3 Technology CPE models. An attacker who can reach the device can authenticate as root and gain unrestricted access, allowing configuration changes, data exfiltration, or further exploitation of the system.

Affected Systems

Affected models are T3 Technology T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03.

Risk and Exploitability

The CVSS score is 9.8. The EPSS score is <1%, indicating a very low exploitation probability, but the presence of a hardcoded password means that the attack path is trivial once connectivity is available. It is not listed in CISA KEV. The problem is purely credential-based and does not rely on any complex code execution. The risk level is high because the attacker can perform any privileged action on the device, and patching or changing the credential is the only effective mitigation.

Generated by OpenCVE AI on June 8, 2026 at 17:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to a version that removes the hardcoded superadmin password.
  • If no firmware update is available, disable or rename the superadmin account and set a strong unique password for any administrative accounts.
  • Restrict network access to the device using firewall rules or VLAN segmentation so that only trusted management hosts can reach it.
  • Enable and monitor audit logs to detect unauthorized login attempts.

Generated by OpenCVE AI on June 8, 2026 at 17:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 08 Jun 2026 17:45:00 +0000

Type Values Removed Values Added
Title Hardcoded Superadmin Password in T3 Technology CPE Devices

Mon, 08 Jun 2026 16:15:00 +0000

Type Values Removed Values Added
Title Hardcoded Root Password in T3 Technology CPE Devices
Weaknesses CWE-798

Mon, 08 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-259
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 05 Jun 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared T3techgroup
T3techgroup cpe
Vendors & Products T3techgroup
T3techgroup cpe

Thu, 04 Jun 2026 15:45:00 +0000

Type Values Removed Values Added
Title Hardcoded Root Password in T3 Technology CPE Devices
Weaknesses CWE-798

Thu, 04 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Description T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded password for root access under the "superadmin" account.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-08T13:55:39.974Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-35905

cve-icon Vulnrichment

Updated: 2026-06-08T13:55:29.366Z

cve-icon NVD

Status : Deferred

Published: 2026-06-04T15:16:50.707

Modified: 2026-06-08T15:16:44.883

Link: CVE-2026-35905

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-08T17:30:06Z

Weaknesses
  • CWE-259

    Use of Hard-coded Password