PT-2026-93697 · Wnc · T-Mobile 5G Box Idu
CVSS v4.0
9.4
Critical
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
WNC T-Mobile 5G Box IDU versions prior to 1.1.0.651412
Description
An OS command injection flaw exists in the '/cgi-bin/portal.cgi' endpoint. The issue occurs because the
cli cookie POST parameter is concatenated into a find command string without proper sanitization. This allows a remote, unauthenticated attacker to execute arbitrary shell commands with root privileges on the operating system.Recommendations
Update to firmware version 1.1.0.651412.
Avoid using the
cli cookie parameter in the '/cgi-bin/portal.cgi' endpoint as a temporary mitigation.Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
T-Mobile 5G Box Idu