PT-2026-93694 · Wnc · T-Mobile 5G Box Idu
CVSS v4.0
9.3
Critical
| Vector | AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
WNC T-Mobile 5G Box IDU router versions prior to 1.1.0.651412
Description
An authenticated attacker can execute arbitrary commands on the shell and gain root access to the system due to a command injection flaw. The issue occurs in the ping functionality within the '/cgi-bin/portal.cgi' endpoint when the system fails to verify and sanitize user-supplied input before incorporating it into a system command. The affected POST parameters are
ping ip, ping size, and ping times.Recommendations
Update to firmware version 1.1.0.651412.
Avoid using the
ping ip, ping size, and ping times parameters in the '/cgi-bin/portal.cgi' endpoint as a temporary mitigation.Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
T-Mobile 5G Box Idu