Description
WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding file in /tmp/login_user. An attacker can bypass authentication by using directory entries such as "." or ".." in the cookie, allowing unauthorized access to the administration panel.This issue has been fixed in firmware version 1.1.0.651412
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass allowing unauthorized administrative access.
Action: Patch Immediately
AI Analysis

Impact

The flaw lies in the portal.cgi component of WNC T‑Mobile 5G Box IDU routers. The session verification routine checks only for the presence of a /tmp/login_user file that matches the cookie value. An attacker can exploit this by inserting directory traversal characters such as "." or ".." into the sessionid cookie, causing the check to succeed without a valid session. This bypass grants the attacker access to the administration panel, enabling full configuration control and potential firmware manipulation.

Affected Systems

This issue affects WNC T-Mobile 5G Box IDU routers that run firmware versions earlier than 1.1.0.651412. Only the routers using this specific hardware and firmware are impacted; newer firmware releases include the fix.

Risk and Exploitability

Given the CVSS score of 8.7, the vulnerability is classified as high severity. The EPSS score of < 1% indicates that known exploitation attempts are rare, and the vulnerability is not yet listed in the CISA KEV catalog. Based on the description, it is inferred that the flaw can be triggered by an unauthenticated attacker who sets the sessionid cookie from a remote web request, implying the attack can occur if network access to the router’s management interface is available. Because the vulnerability does not require privileged credentials to reach the vulnerable endpoint, its likelihood of exploitation is non‑zero but low compared to other high‑impact flaws.

Generated by OpenCVE AI on September 18, 2026 at 03:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade router firmware to version 1.1.0.651412 or later.
  • If an immediate firmware upgrade is not feasible, block or restrict HTTP access to the portal.cgi endpoint from untrusted networks using firewall or ACLs.
  • Configure the router to reject sessionid cookie values containing directory traversal characters or any non‑alphanumeric characters, ensuring that only valid session identifiers are accepted.

Generated by OpenCVE AI on September 18, 2026 at 03:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding file in /tmp/login_user. An attacker can bypass authentication by using directory entries such as "." or ".." in the cookie, allowing unauthorized access to the administration panel.This issue has been fixed in firmware version 1.1.0.651412
Title Session auth bypass via cookie value in T-Mobile 5G Box IDU routers
First Time appeared Wnc
Wnc t-mobile 5g Box Idu
Weaknesses CWE-290
CPEs cpe:2.3:a:wnc:t-mobile_5g_box_idu:*:*:*:*:*:*:*:*
Vendors & Products Wnc
Wnc t-mobile 5g Box Idu
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Wnc T-mobile 5g Box Idu
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-16T17:41:03.847Z

Reserved: 2026-04-15T11:10:34.849Z

Link: CVE-2026-40854

cve-icon Vulnrichment

Updated: 2026-09-16T17:40:55.117Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T12:17:03.540

Modified: 2026-09-28T23:10:00.143

Link: CVE-2026-40854

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:00:03Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing