WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value parameter, accepting any arbitrary value as valid. This allows a remote attack
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WNC | T-Mobile 5G Box IDU | 0 ~ 1.1.0.651412 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58146 | 9.4 CRITICAL | Unauthorized remote code execution in T-Mobile 5G Box IDU routers |
| CVE-2026-58147 | 9.3 CRITICAL | Authorized remote code execution via password change functionality in T-Mobile 5G Box IDU |
| CVE-2026-40855 | 9.3 CRITICAL | Command Injection in T-Mobile 5G Box IDU router via ping functionality |
| CVE-2026-40854 | 8.7 HIGH | Session auth bypass via cookie value in T-Mobile 5G Box IDU routers |
| CVE-2026-40856 | 7.1 HIGH | Config disclosure in T-Mobile 5G Box IDU routers |
No comments yet