Impact
The T‑Mobile 5G Box IDU router contains a command injection flaw in the ping function of the /cgi-bin/portal.cgi web endpoint. Unfiltered POST parameters ping_ip, ping_size, and ping_times are passed directly to a system command, allowing an authenticated caller to run arbitrary shell commands with root privileges. This is a classic CWE‑78 misuse of command execution. The resulting impact is full system compromise, as the attacker can execute any command on the device’s operating system.
Affected Systems
The affected product is the WNC T‑Mobile 5G Box IDU router. Firmware versions prior to 1.1.0.651412 are vulnerable; the fix is included in that firmware release. All earlier releases should be considered at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.3, indicating high severity, and an EPSS score of 1%, suggesting a modest likelihood of exploitation. It is not currently listed in CISA’s KEV catalog. Exploitation requires authenticated access to the router’s web interface; an attacker with valid credentials can trigger the flaw by submitting crafted POST data to the ping endpoint, thereby executing arbitrary commands as root.
OpenCVE Enrichment