PT-2026-93695 · Wnc · T-Mobile 5G Box Idu

·

CVE-2026-40856

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

7.1

High

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions WNC T-Mobile 5G Box IDU versions prior to 1.1.0.651412
Description Improper access control allows a remote attacker to access the 'wnc maccheck.cgi' endpoint without authentication. This enables the retrieval of sensitive configuration data, such as the administrator web password, WiFi passphrase, and technical device information.
Recommendations Update to firmware version 1.1.0.651412.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40856

Affected Products

T-Mobile 5G Box Idu