CVE-2026-40854
largeAuthentication Bypass in WNC T-Mobile 5G Box IDU Router
The WNC T-Mobile 5G Box IDU router contains an authentication bypass (CWE-290) in its portal.cgi component, where session verification only checks that a file matching the sessionid cookie value exists under /tmp/login_user. Because that check can be satisfied with directory entries such as '.' or '..', an unauthenticated attacker can forge a cookie value that passes validation. Successful bypass grants unauthorized access to the router's administration panel, where high-impact configuration and control actions are possible (CVSS 4.0 rates confidentiality, integrity, and availability impact as high). The attack vector is adjacent (AV:A), meaning the attacker must already be on the local network, such as a Wi-Fi or LAN client. No public proof-of-concept, in-the-wild exploitation, or KEV listing is known; affected users should move to firmware 1.1.0.651412 or later.
What to do: Upgrade the router to firmware 1.1.0.651412 or later and verify the installed version in the administration panel. Because exploitation requires adjacent network access, avoid connecting untrusted devices to the router's LAN/guest networks until updated, and confirm the administration interface is not reachable from the WAN side.
| WNC (T-Mobile-branded) T-Mobile 5G Box IDU router | firmware prior to 1.1.0.651412 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding file in /tmp/login_user. An attacker can bypass authentication by using directory entries such as "." or ".." in the cookie, allowing unauthorized access to the administration panel.This issue has been fixed in firmware version 1.1.0.651412
- Weakness
- CWE-290
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.