🔐 CVE Alert

CVE-2026-58147

UNKNOWN 0.0

Authorized remote code execution via password change functionality in T-Mobile 5G Box IDU routers

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality. The application improperly neutralizes special elements in the http_passwd_hidden and http_passwdConfirm_hidden parameters, allowing an authenticated attacker to execute arbitrary commands on the underlying operating system with root privileges.This issue has been fixed in firmware version 1.1.0.651412

CWE CWE-78
Vendor wnc
Product t-mobile 5g box idu
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for wnc t-mobile 5g box idu

Be the first to know when new unknown vulnerabilities affecting wnc t-mobile 5g box idu are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

WNC / T-Mobile 5G Box IDU
0 < 1.1.0.651412

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.pl: https://cert.pl/posts/2026/09/CVE-2026-40854

Credits

Patryk Bogdan Adam Borczyk