WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality within the /cgi-bin/portal.cgi endpoint, specifically affecting the ping_ip, ping_size, and ping_times POST parameters. The root cause is the failure to verify and sanitize user-supplied input before incorporating it into a system command. This allows an authenticated attacker to execute arbitrary commands on the shell and gain root access to the system.This issue has been fixed in firmware versionĀ 1.1.0.651412
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://cert.pl/posts/2026/09/CVE-2026-40854 |
|
History
Wed, 16 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality within the /cgi-bin/portal.cgi endpoint, specifically affecting the ping_ip, ping_size, and ping_times POST parameters. The root cause is the failure to verify and sanitize user-supplied input before incorporating it into a system command. This allows an authenticated attacker to execute arbitrary commands on the shell and gain root access to the system.This issue has been fixed in firmware versionĀ 1.1.0.651412 | |
| Title | Command Injection in T-Mobile 5G Box IDU router via ping functionality | |
| First Time appeared |
Wnc
Wnc t-mobile 5g Box Idu |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:wnc:t-mobile_5g_box_idu:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wnc
Wnc t-mobile 5g Box Idu |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-09-16T11:21:11.939Z
Reserved: 2026-04-15T11:10:34.849Z
Link: CVE-2026-40855
No data.
Status : Received
Published: 2026-09-16T12:17:03.673
Modified: 2026-09-16T12:17:03.673
Link: CVE-2026-40855
No data.
OpenCVE Enrichment
No data.
Weaknesses