Wnc · T-Mobile 5G Box Idu · CVE-2026-40855
**Name of the Vulnerable Software and Affected Versions**
WNC T-Mobile 5G Box IDU router versions prior to 1.1.0.651412
**Description**
An authenticated attacker can execute arbitrary commands on the shell and gain root access to the system due to a command injection flaw. The issue occurs in the ping functionality within the '/cgi-bin/portal.cgi' endpoint when the system fails to verify and sanitize user-supplied input before incorporating it into a system command. The affected POST parameters are `ping ip`, `ping size`, and `ping times`.
**Recommendations**
Update to firmware version 1.1.0.651412.
Avoid using the `ping ip`, `ping size`, and `ping times` parameters in the '/cgi-bin/portal.cgi' endpoint as a temporary mitigation.