🔐 CVE Alert

CVE-2026-58146

UNKNOWN 0.0

Unauthorized remote code execution in T-Mobile 5G Box IDU routers

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the /cgi-bin/portal.cgi endpoint, specifically through the cli_cookie POST parameter. The cli_cookie parameter value is directly concatenated into a find command string without proper sanitization. This allows a remote, unauthenticated attacker to inject and execute arbitrary shell commands as root on the underlying operating system. This issue has been fixed in firmware version 1.1.0.651412

CWE CWE-78
Vendor wnc
Product t-mobile 5g box idu
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for wnc t-mobile 5g box idu

Be the first to know when new unknown vulnerabilities affecting wnc t-mobile 5g box idu are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

WNC / T-Mobile 5G Box IDU
0 < 1.1.0.651412

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.pl: https://cert.pl/posts/2026/09/CVE-2026-40854

Credits

Patryk Bogdan Adam Borczyk