WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgi endpoint, which is accessible without authentication. It allows a remote attacker to retrieve sensitive configuration data, including the
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WNC | T-Mobile 5G Box IDU | 0 ~ 1.1.0.651412 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58146 | 9.4 CRITICAL | Unauthorized remote code execution in T-Mobile 5G Box IDU routers |
| CVE-2026-58147 | 9.3 CRITICAL | Authorized remote code execution via password change functionality in T-Mobile 5G Box IDU |
| CVE-2026-40855 | 9.3 CRITICAL | Command Injection in T-Mobile 5G Box IDU router via ping functionality |
| CVE-2026-40854 | 8.7 HIGH | Session auth bypass via cookie value in T-Mobile 5G Box IDU routers |
| CVE-2026-40857 | 8.4 HIGH | CSRF token bypass in T-Mobile 5G Box IDU routers |
No comments yet