CVE-2026-40856
moderateUnauthenticated Configuration Disclosure in WNC T-Mobile 5G Box IDU Router
The WNC T-Mobile 5G Box IDU router has an improper access control flaw (CWE-306): the wnc_maccheck.cgi endpoint can be reached without any authentication. An unauthenticated attacker on an adjacent network (per the CVSS 4.0 attack vector, e.g., the same LAN or Wi-Fi segment) can query this endpoint and pull sensitive configuration data. The disclosed data includes the administrator web password, the Wi-Fi passphrase, and technical device information, potentially allowing takeover of router administration or access to the wireless network. All users of this router running firmware older than 1.1.0.651412 are affected. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known.
What to do: Upgrade the router to firmware version 1.1.0.651412 or later via the device's firmware update mechanism. Until patched, restrict the management interface to a trusted LAN segment and confirm remote/WAN administration is disabled. Because the admin password and Wi-Fi passphrase are recoverable by local attackers, rotate both credentials after updating if untrusted devices may have had local network access.
| WNC (Wistron NeWeb Corporation) T-Mobile 5G Box IDU router | All firmware versions prior to 1.1.0.651412 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgi endpoint, which is accessible without authentication. It allows a remote attacker to retrieve sensitive configuration data, including the administrator web password, WiFi passphrase, and technical device information.This issue has been fixed in firmware version 1.1.0.651412
- Weakness
- CWE-306
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.