WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality. The application improperly neutralizes special elements in the http_passwd_hidden and http_passwdConfirm_hidden parameters, allowing an authenticated attacker to execute arbitrary commands on the underlying operating system with root privileges.This issue has been fixed in firmware version 1.1.0.651412
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://cert.pl/posts/2026/09/CVE-2026-40854 |
|
History
Wed, 16 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality. The application improperly neutralizes special elements in the http_passwd_hidden and http_passwdConfirm_hidden parameters, allowing an authenticated attacker to execute arbitrary commands on the underlying operating system with root privileges.This issue has been fixed in firmware version 1.1.0.651412 | |
| Title | Authorized remote code execution via password change functionality in T-Mobile 5G Box IDU routers | |
| First Time appeared |
Wnc
Wnc t-mobile 5g Box Idu |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:wnc:t-mobile_5g_box_idu:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wnc
Wnc t-mobile 5g Box Idu |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-09-16T11:21:16.720Z
Reserved: 2026-06-29T14:19:37.080Z
Link: CVE-2026-58147
No data.
Status : Received
Published: 2026-09-16T12:17:05.103
Modified: 2026-09-16T12:17:05.103
Link: CVE-2026-58147
No data.
OpenCVE Enrichment
No data.
Weaknesses