CVE-2026-40855
largeAuthenticated Command Injection in WNC T-Mobile 5G Box IDU Router
The WNC-manufactured T-Mobile 5G Box IDU router contains a command injection flaw (CWE-78) in the ping functionality of its /cgi-bin/portal.cgi web endpoint. The ping_ip, ping_size, and ping_times POST parameters are incorporated into a system command without verification or sanitization, allowing an attacker to append arbitrary shell commands. Because the CVSS vector requires adjacent-network access and high privileges, an attacker needs valid credentials on the router's portal interface, but once authenticated they can execute arbitrary commands and gain root access, fully compromising the gateway. All units running firmware before 1.1.0.651412 are affected, and a fixed firmware is available. No public proof-of-concept is known, the issue is not in CISA's KEV, and no in-the-wild exploitation has been confirmed.
What to do: Upgrade the router to firmware 1.1.0.651412 or later via the admin portal or carrier-pushed updates, and verify the running version in the web interface. Because exploitation requires portal credentials, set a strong admin password, keep remote/WAN management of the portal disabled, and limit admin access to trusted LAN clients.
| WNC (Wistron NeWeb) T-Mobile 5G Box IDU router | firmware prior to 1.1.0.651412 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality within the /cgi-bin/portal.cgi endpoint, specifically affecting the ping_ip, ping_size, and ping_times POST parameters. The root cause is the failure to verify and sanitize user-supplied input before incorporating it into a system command. This allows an authenticated attacker to execute arbitrary commands on the shell and gain root access to the system.This issue has been fixed in firmware version 1.1.0.651412
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.