Description
WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality within the /cgi-bin/portal.cgi endpoint, specifically affecting the ping_ip, ping_size, and ping_times POST parameters. The root cause is the failure to verify and sanitize user-supplied input before incorporating it into a system command. This allows an authenticated attacker to execute arbitrary commands on the shell and gain root access to the system.This issue has been fixed in firmware version 1.1.0.651412
Published: 2026-09-16
Score: 9.3 Critical
EPSS: 1.6% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The T‑Mobile 5G Box IDU router contains a command injection flaw in the ping function of the /cgi-bin/portal.cgi web endpoint. Unfiltered POST parameters ping_ip, ping_size, and ping_times are passed directly to a system command, allowing an authenticated caller to run arbitrary shell commands with root privileges. This is a classic CWE‑78 misuse of command execution. The resulting impact is full system compromise, as the attacker can execute any command on the device’s operating system.

Affected Systems

The affected product is the WNC T‑Mobile 5G Box IDU router. Firmware versions prior to 1.1.0.651412 are vulnerable; the fix is included in that firmware release. All earlier releases should be considered at risk.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.3, indicating high severity, and an EPSS score of 1%, suggesting a modest likelihood of exploitation. It is not currently listed in CISA’s KEV catalog. Exploitation requires authenticated access to the router’s web interface; an attacker with valid credentials can trigger the flaw by submitting crafted POST data to the ping endpoint, thereby executing arbitrary commands as root.

Generated by OpenCVE AI on September 18, 2026 at 02:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the firmware update to version 1.1.0.651412 or later to remove the vulnerability.
  • If a firmware update is not immediately available, disable the ping feature in the router’s web interface or remove the /cgi-bin/portal.cgi endpoint from external access.
  • Ensure that admin credentials are strong and that access to the router’s management interface is restricted to trusted network segments or VPNs.
  • Monitor the router for unauthorized access attempts and log all management session activity for audit.

Generated by OpenCVE AI on September 18, 2026 at 02:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality within the /cgi-bin/portal.cgi endpoint, specifically affecting the ping_ip, ping_size, and ping_times POST parameters. The root cause is the failure to verify and sanitize user-supplied input before incorporating it into a system command. This allows an authenticated attacker to execute arbitrary commands on the shell and gain root access to the system.This issue has been fixed in firmware version 1.1.0.651412
Title Command Injection in T-Mobile 5G Box IDU router via ping functionality
First Time appeared Wnc
Wnc t-mobile 5g Box Idu
Weaknesses CWE-78
CPEs cpe:2.3:a:wnc:t-mobile_5g_box_idu:*:*:*:*:*:*:*:*
Vendors & Products Wnc
Wnc t-mobile 5g Box Idu
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Wnc T-mobile 5g Box Idu
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-16T16:01:54.453Z

Reserved: 2026-04-15T11:10:34.849Z

Link: CVE-2026-40855

cve-icon Vulnrichment

Updated: 2026-09-16T16:01:51.268Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T12:17:03.673

Modified: 2026-09-28T23:10:00.143

Link: CVE-2026-40855

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:00:09Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')