WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality within the /cgi-bin/portal.cgi endpoint, specifically affecting the ping_ip, ping_size, and ping_times POST parameters. The root cause is th
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WNC | T-Mobile 5G Box IDU | 0 ~ 1.1.0.651412 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58146 | 9.4 CRITICAL | Unauthorized remote code execution in T-Mobile 5G Box IDU routers |
| CVE-2026-58147 | 9.3 CRITICAL | Authorized remote code execution via password change functionality in T-Mobile 5G Box IDU |
| CVE-2026-40854 | 8.7 HIGH | Session auth bypass via cookie value in T-Mobile 5G Box IDU routers |
| CVE-2026-40857 | 8.4 HIGH | CSRF token bypass in T-Mobile 5G Box IDU routers |
| CVE-2026-40856 | 7.1 HIGH | Config disclosure in T-Mobile 5G Box IDU routers |
No comments yet