Impact
The flaw lies in the portal.cgi component of WNC T‑Mobile 5G Box IDU routers. The session verification routine checks only for the presence of a /tmp/login_user file that matches the cookie value. An attacker can exploit this by inserting directory traversal characters such as "." or ".." into the sessionid cookie, causing the check to succeed without a valid session. This bypass grants the attacker access to the administration panel, enabling full configuration control and potential firmware manipulation.
Affected Systems
This issue affects WNC T-Mobile 5G Box IDU routers that run firmware versions earlier than 1.1.0.651412. Only the routers using this specific hardware and firmware are impacted; newer firmware releases include the fix.
Risk and Exploitability
Given the CVSS score of 8.7, the vulnerability is classified as high severity. The EPSS score of < 1% indicates that known exploitation attempts are rare, and the vulnerability is not yet listed in the CISA KEV catalog. Based on the description, it is inferred that the flaw can be triggered by an unauthenticated attacker who sets the sessionid cookie from a remote web request, implying the attack can occur if network access to the router’s management interface is available. Because the vulnerability does not require privileged credentials to reach the vulnerable endpoint, its likelihood of exploitation is non‑zero but low compared to other high‑impact flaws.
OpenCVE Enrichment