ZeroHour

CVE-2026-40854

large

Authentication Bypass in WNC T-Mobile 5G Box IDU Router

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

The WNC T-Mobile 5G Box IDU router contains an authentication bypass (CWE-290) in its portal.cgi component, where session verification only checks that a file matching the sessionid cookie value exists under /tmp/login_user. Because that check can be satisfied with directory entries such as '.' or '..', an unauthenticated attacker can forge a cookie value that passes validation. Successful bypass grants unauthorized access to the router's administration panel, where high-impact configuration and control actions are possible (CVSS 4.0 rates confidentiality, integrity, and availability impact as high). The attack vector is adjacent (AV:A), meaning the attacker must already be on the local network, such as a Wi-Fi or LAN client. No public proof-of-concept, in-the-wild exploitation, or KEV listing is known; affected users should move to firmware 1.1.0.651412 or later.

What to do: Upgrade the router to firmware 1.1.0.651412 or later and verify the installed version in the administration panel. Because exploitation requires adjacent network access, avoid connecting untrusted devices to the router's LAN/guest networks until updated, and confirm the administration interface is not reachable from the WAN side.

Affected
WNC (T-Mobile-branded) T-Mobile 5G Box IDU routerfirmware prior to 1.1.0.651412
Estimated exposure
largeplausibly on the order of hundreds of thousands of deployed units — T-Mobile's 5G Home Internet service serves several million subscribers and this WNC gateway is one of the models distributed to those customers, so a six-figure device count is plausible, though exact model-level deployment numbers are not…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding file in /tmp/login_user. An attacker can bypass authentication by using directory entries such as "." or ".." in the cookie, allowing unauthorized access to the administration panel.This issue has been fixed in firmware version 1.1.0.651412

Weakness
CWE-290
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.