Description
WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding file in /tmp/login_user. An attacker can bypass authentication by using directory entries such as "." or ".." in the cookie, allowing unauthorized access to the administration panel.This issue has been fixed in firmware versionĀ 1.1.0.651412
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://cert.pl/posts/2026/09/CVE-2026-40854 |
|
History
Wed, 16 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding file in /tmp/login_user. An attacker can bypass authentication by using directory entries such as "." or ".." in the cookie, allowing unauthorized access to the administration panel.This issue has been fixed in firmware versionĀ 1.1.0.651412 | |
| Title | Session auth bypass via cookie value in T-Mobile 5G Box IDU routers | |
| First Time appeared |
Wnc
Wnc t-mobile 5g Box Idu |
|
| Weaknesses | CWE-290 | |
| CPEs | cpe:2.3:a:wnc:t-mobile_5g_box_idu:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wnc
Wnc t-mobile 5g Box Idu |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-09-16T11:21:10.202Z
Reserved: 2026-04-15T11:10:34.849Z
Link: CVE-2026-40854
No data.
Status : Received
Published: 2026-09-16T12:17:03.540
Modified: 2026-09-16T12:17:03.540
Link: CVE-2026-40854
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-290
Authentication Bypass by Spoofing