ZeroHour

CVE-2026-58147

large

Authenticated OS Command Injection in WNC T-Mobile 5G Box IDU Router

CVSS 4.0
9.3 critical
EPSS
Published
()
Modified
AI analysis

WNC's T-Mobile 5G Box IDU router contains an OS command injection flaw (CWE-78) in the portal.cgi component's password change functionality. The web application fails to properly neutralize special characters in the http_passwd_hidden and http_passwdConfirm_hidden parameters, allowing submitted values to be interpreted as operating system commands. An attacker who is already authenticated to the router's management portal (CVSS 4.0 rates privileges required as high, with adjacent-network attack vector) can leverage this to execute arbitrary commands with root privileges on the device's underlying OS. Any subscriber or operator running affected firmware on this gateway is exposed, primarily to attackers on the local network or connected clients. No exploitation in the wild, public proof-of-concept, or KEV listing is currently known, and a fixed firmware version (1.1.0.651412) has been released.

What to do: Upgrade the gateway to firmware version 1.1.0.651412 or later, checking the current version in the router's admin portal. Restrict management-portal access to trusted LAN clients, ensure strong non-default admin credentials are set, and monitor for client compromise, since exploitation requires valid portal authentication from an adjacent network.

Affected
WNC (Wistron NeWeb Corp.) T-Mobile 5G Box IDU routerAll firmware versions prior to 1.1.0.651412
Estimated exposure
largeplausibly on the order of hundreds of thousands of devices (a subset of T-Mobile's multi-million-customer 5G Home Internet base using the WNC IDU gateway) — T-Mobile's 5G Home Internet service has millions of subscribers in the US, and this WNC-manufactured IDU gateway is one of the distributed customer-premises models, but the precise share of units running vulnerable pre-1.1.0.651412…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality. The application improperly neutralizes special elements in the http_passwd_hidden and http_passwdConfirm_hidden parameters, allowing an authenticated attacker to execute arbitrary commands on the underlying operating system with root privileges.This issue has been fixed in firmware version 1.1.0.651412

Weakness
CWE-78
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.