PT-2026-93697 · Wnc · T-Mobile 5G Box Idu

·

CVE-2026-58146

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

9.4

Critical

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions WNC T-Mobile 5G Box IDU versions prior to 1.1.0.651412
Description An OS command injection flaw exists in the '/cgi-bin/portal.cgi' endpoint. The issue occurs because the cli cookie POST parameter is concatenated into a find command string without proper sanitization. This allows a remote, unauthenticated attacker to execute arbitrary shell commands with root privileges on the operating system.
Recommendations Update to firmware version 1.1.0.651412. Avoid using the cli cookie parameter in the '/cgi-bin/portal.cgi' endpoint as a temporary mitigation.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58146

Affected Products

T-Mobile 5G Box Idu