🔐 CVE Alert

CVE-2026-40856

UNKNOWN 0.0

Config disclosure in T-Mobile 5G Box IDU routers

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgi endpoint, which is accessible without authentication. It allows a remote attacker to retrieve sensitive configuration data, including the administrator web password, WiFi passphrase, and technical device information.This issue has been fixed in firmware version 1.1.0.651412

CWE CWE-306
Vendor wnc
Product t-mobile 5g box idu
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for wnc t-mobile 5g box idu

Be the first to know when new unknown vulnerabilities affecting wnc t-mobile 5g box idu are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

WNC / T-Mobile 5G Box IDU
0 < 1.1.0.651412

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.pl: https://cert.pl/posts/2026/09/CVE-2026-40854

Credits

Patryk Bogdan Adam Borczyk