PT-2026-93694 · Wnc · T-Mobile 5G Box Idu

·

CVE-2026-40855

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

9.3

Critical

VectorAV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions WNC T-Mobile 5G Box IDU router versions prior to 1.1.0.651412
Description An authenticated attacker can execute arbitrary commands on the shell and gain root access to the system due to a command injection flaw. The issue occurs in the ping functionality within the '/cgi-bin/portal.cgi' endpoint when the system fails to verify and sanitize user-supplied input before incorporating it into a system command. The affected POST parameters are ping ip, ping size, and ping times.
Recommendations Update to firmware version 1.1.0.651412. Avoid using the ping ip, ping size, and ping times parameters in the '/cgi-bin/portal.cgi' endpoint as a temporary mitigation.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40855

Affected Products

T-Mobile 5G Box Idu