CVE-2026-35906

Critical severity, CVSS 9.6. EPSS: 0.8% chance of exploitation in the next 30 days.

An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated attackers to execute arbitrary system commands as root via supplying a crafted HTTP query string.

Published 2026-06-04. Last modified 2026-07-22.