PT-2026-93693 · Wnc · T-Mobile 5G Box Idu
CVSS v4.0
8.7
High
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
WNC T-Mobile 5G Box IDU router versions prior to 1.1.0.651412
Description
The
portal.cgi component contains two security issues. First, an authentication bypass exists because the session verification mechanism improperly validates the sessionid cookie by checking for a file in /tmp/login user. An attacker can gain unauthorized access to the administration panel by using directory entries like . or .. in the cookie. Second, an OS command injection exists in the password change functionality. The application fails to neutralize special elements in the http passwd hidden and http passwdConfirm hidden parameters, allowing an authenticated attacker to execute arbitrary commands on the operating system with root privileges.Recommendations
Update to firmware version 1.1.0.651412.
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
T-Mobile 5G Box Idu