ZeroHour

CVE-2026-40855

large

Authenticated Command Injection in WNC T-Mobile 5G Box IDU Router

CVSS 4.0
9.3 critical
EPSS
Published
()
Modified
AI analysis

The WNC-manufactured T-Mobile 5G Box IDU router contains a command injection flaw (CWE-78) in the ping functionality of its /cgi-bin/portal.cgi web endpoint. The ping_ip, ping_size, and ping_times POST parameters are incorporated into a system command without verification or sanitization, allowing an attacker to append arbitrary shell commands. Because the CVSS vector requires adjacent-network access and high privileges, an attacker needs valid credentials on the router's portal interface, but once authenticated they can execute arbitrary commands and gain root access, fully compromising the gateway. All units running firmware before 1.1.0.651412 are affected, and a fixed firmware is available. No public proof-of-concept is known, the issue is not in CISA's KEV, and no in-the-wild exploitation has been confirmed.

What to do: Upgrade the router to firmware 1.1.0.651412 or later via the admin portal or carrier-pushed updates, and verify the running version in the web interface. Because exploitation requires portal credentials, set a strong admin password, keep remote/WAN management of the portal disabled, and limit admin access to trusted LAN clients.

Affected
WNC (Wistron NeWeb) T-Mobile 5G Box IDU routerfirmware prior to 1.1.0.651412
Estimated exposure
large≈100,000–1,000,000 subscriber-deployed gateway devices, with far fewer reachable remotely — Carrier-supplied 5G home gateways are typically deployed in fleets of hundreds of thousands to millions of subscriber households, but the installed base of this specific WNC IDU model is not published, and the flaw is LAN-side and requires…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality within the /cgi-bin/portal.cgi endpoint, specifically affecting the ping_ip, ping_size, and ping_times POST parameters. The root cause is the failure to verify and sanitize user-supplied input before incorporating it into a system command. This allows an authenticated attacker to execute arbitrary commands on the shell and gain root access to the system.This issue has been fixed in firmware version 1.1.0.651412

Weakness
CWE-78
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.