PT-2026-93693 · Wnc · T-Mobile 5G Box Idu

·

CVE-2026-40854

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

8.7

High

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions WNC T-Mobile 5G Box IDU router versions prior to 1.1.0.651412
Description The portal.cgi component contains two security issues. First, an authentication bypass exists because the session verification mechanism improperly validates the sessionid cookie by checking for a file in /tmp/login user. An attacker can gain unauthorized access to the administration panel by using directory entries like . or .. in the cookie. Second, an OS command injection exists in the password change functionality. The application fails to neutralize special elements in the http passwd hidden and http passwdConfirm hidden parameters, allowing an authenticated attacker to execute arbitrary commands on the operating system with root privileges.
Recommendations Update to firmware version 1.1.0.651412.

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40854

Affected Products

T-Mobile 5G Box Idu