Impact
An undocumented debug CGI endpoint in T3 Technology CPE devices allows unauthenticated attackers to execute arbitrary system commands as root by sending a crafted HTTP query string. This vulnerability is a classic command injection (CWE-78) that bypasses all authentication mechanisms, giving an attacker full control over the affected system and compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerable products are the T3 Technology CPE models T625Pro running firmware version 1.0.07 and T6825G running firmware version 1.0.03. No other versions or models are listed as affected.
Risk and Exploitability
The attack vector requires network reachability to the device; a remote attacker can simply send a malicious HTTP request to the endpoint. The vulnerability permits execution of system commands with root privilege, making it a high-severity issue. Since no CVSS score or EPSS estimate is publicly available, the potential for exploitation remains high, and the vulnerability is not currently listed in CISA’s KEV catalog.
OpenCVE Enrichment