PT-2026-93698 · Wnc · T-Mobile 5G Box Idu
CVSS v4.0
9.3
Critical
| Vector | AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
WNC T-Mobile 5G Box IDU router versions prior to 1.1.0.651412
Description
The password change functionality within the 'portal.cgi' component contains an OS command injection flaw. The application fails to properly neutralize special elements in the
http passwd hidden and http passwdConfirm hidden parameters. This allows an authenticated attacker to execute arbitrary commands on the underlying operating system with root privileges.Recommendations
Update to firmware version 1.1.0.651412.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
T-Mobile 5G Box Idu