CVE-2026-35904
Deferred
Deferred - Pending Action
Incorrect Access Control in T3 Technology CPE Models Enables Telnet Service
Publication date: 2026-06-04
Last updated on: 2026-06-08
Assigner: MITRE
Description
Description
Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 allows unauthorized attackers to enable the Telnet service via sending a crafted request to a vulnerable CGI component.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| t3_technology | t625pro | 1.0.07 |
| t3_technology | t6825g | 1.0.03 |
| t3_technology | t7281 | 1.0.03 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |