An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated attackers to execute arbitrary system commands as root via supplying a crafted HTTP query string.
An undocumented debug
Exploit
CVE-2026-35906
NVD
Refer to CVE-2026-35906 NVD advisory