Impact
The vulnerability is a hardcoded password for the superadmin account on specific T3 Technology CPE models. An attacker who can reach the device can authenticate as root and gain unrestricted access, allowing configuration changes, data exfiltration, or further exploitation of the system.
Affected Systems
Affected models are T3 Technology T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03.
Risk and Exploitability
No EPSS information and the vulnerability is not listed in CISA KEV, but the presence of a hardcoded password means that the attack path is trivial once connectivity is available. The problem is purely credential-based and does not rely on any complex code execution. The risk level is high because the attacker can perform any privileged action on the device, and patching or changing the credential is the only effective mitigation.
OpenCVE Enrichment