WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the /cgi-bin/portal.cgi endpoint, specifically through the cli_cookie POST parameter. The cli_cookie parameter value is directly concatenated in
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WNC | T-Mobile 5G Box IDU | 0 ~ 1.1.0.651412 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58147 | 9.3 CRITICAL | Authorized remote code execution via password change functionality in T-Mobile 5G Box IDU |
| CVE-2026-40855 | 9.3 CRITICAL | Command Injection in T-Mobile 5G Box IDU router via ping functionality |
| CVE-2026-40854 | 8.7 HIGH | Session auth bypass via cookie value in T-Mobile 5G Box IDU routers |
| CVE-2026-40857 | 8.4 HIGH | CSRF token bypass in T-Mobile 5G Box IDU routers |
| CVE-2026-40856 | 7.1 HIGH | Config disclosure in T-Mobile 5G Box IDU routers |
No comments yet