WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality. The application improperly neutralizes special elements in the http_passwd_hidden and http_passwdConfirm_hidden parameter
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WNC | T-Mobile 5G Box IDU | 0 ~ 1.1.0.651412 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58146 | 9.4 CRITICAL | Unauthorized remote code execution in T-Mobile 5G Box IDU routers |
| CVE-2026-40855 | 9.3 CRITICAL | Command Injection in T-Mobile 5G Box IDU router via ping functionality |
| CVE-2026-40854 | 8.7 HIGH | Session auth bypass via cookie value in T-Mobile 5G Box IDU routers |
| CVE-2026-40857 | 8.4 HIGH | CSRF token bypass in T-Mobile 5G Box IDU routers |
| CVE-2026-40856 | 7.1 HIGH | Config disclosure in T-Mobile 5G Box IDU routers |
No comments yet