All 6 CVE vulnerabilities found in T-Mobile 5G Box IDU, with AI-generated Chinese analysis, references, and POCs.
Vendor: WNC
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-58147 | Authorized remote code execution via password change functionality in T-Mobile 5G Box IDU routers CWE-78 | 9.3 | Critical | 2026-09-16 |
| CVE-2026-58146 | Unauthorized remote code execution in T-Mobile 5G Box IDU routers CWE-78 | 9.4 | Critical | 2026-09-16 |
| CVE-2026-40857 | CSRF token bypass in T-Mobile 5G Box IDU routers CWE-352 | 8.4 | High | 2026-09-16 |
| CVE-2026-40856 | Config disclosure in T-Mobile 5G Box IDU routers CWE-306 | 7.1 | High | 2026-09-16 |
| CVE-2026-40855 | Command Injection in T-Mobile 5G Box IDU router via ping functionality CWE-78 | 9.3 | Critical | 2026-09-16 |
| CVE-2026-40854 | Session auth bypass via cookie value in T-Mobile 5G Box IDU routers CWE-290 | 8.7 | High | 2026-09-16 |
All 6 known CVE vulnerabilities affecting T-Mobile 5G Box IDU with full Chinese analysis, references, and POCs where available.