CVE-2026-58147
largeAuthenticated OS Command Injection in WNC T-Mobile 5G Box IDU Router
WNC's T-Mobile 5G Box IDU router contains an OS command injection flaw (CWE-78) in the portal.cgi component's password change functionality. The web application fails to properly neutralize special characters in the http_passwd_hidden and http_passwdConfirm_hidden parameters, allowing submitted values to be interpreted as operating system commands. An attacker who is already authenticated to the router's management portal (CVSS 4.0 rates privileges required as high, with adjacent-network attack vector) can leverage this to execute arbitrary commands with root privileges on the device's underlying OS. Any subscriber or operator running affected firmware on this gateway is exposed, primarily to attackers on the local network or connected clients. No exploitation in the wild, public proof-of-concept, or KEV listing is currently known, and a fixed firmware version (1.1.0.651412) has been released.
What to do: Upgrade the gateway to firmware version 1.1.0.651412 or later, checking the current version in the router's admin portal. Restrict management-portal access to trusted LAN clients, ensure strong non-default admin credentials are set, and monitor for client compromise, since exploitation requires valid portal authentication from an adjacent network.
| WNC (Wistron NeWeb Corp.) T-Mobile 5G Box IDU router | All firmware versions prior to 1.1.0.651412 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality. The application improperly neutralizes special elements in the http_passwd_hidden and http_passwdConfirm_hidden parameters, allowing an authenticated attacker to execute arbitrary commands on the underlying operating system with root privileges.This issue has been fixed in firmware version 1.1.0.651412
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.