Description
WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgi endpoint, which is accessible without authentication. It allows a remote attacker to retrieve sensitive configuration data, including the administrator web password, WiFi passphrase, and technical device information.This issue has been fixed in firmware version 1.1.0.651412
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Upgrade Firmware
AI Analysis

Impact

The vulnerable endpoint wnc_maccheck.cgi allows any network host to retrieve the router's configuration without authentication, exposing administrator credentials, Wi‑Fi keys and other device parameters. This improper access control flaw, classified as CWE‑306, means that a remote attacker can read confidential settings that should be restricted to privileged users. The immediate result is full visibility into the device's administrative secrets and wireless network details.

Affected Systems

This flaw affects WNC's T‑Mobile 5G Box IDU routers. The vulnerability is present in firmware versions earlier than 1.1.0.651412, the patch that addresses the issue. No other vendors or product lines are cited.

Risk and Exploitability

The CVSS score of 7.1 signifies a moderate to high severity, while the EPSS score of less than 1 % indicates that exploit likelihood is currently very low. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known widespread exploitation. Attackers could remotely trigger the CGI endpoint over the WAN or LAN ports and obtain sensitive configuration files, potentially enabling further lateral movement or credential-based attacks. Because the vulnerability requires only unauthenticated access to the HTTP interface, anyone with network reach can exploit it.

Generated by OpenCVE AI on September 18, 2026 at 02:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the device firmware to version 1.1.0.651412 or later, which removes the unauthenticated access to the CGI endpoint.
  • Isolate the router by placing it on a separate VLAN or applying firewall rules to restrict inbound traffic to the WAN interface, reducing exposure to external hosts.
  • Enable logging and monitor authentication logs for repeated requests to wnc_maccheck.cgi, then investigate any anomalous activity.

Generated by OpenCVE AI on September 18, 2026 at 02:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgi endpoint, which is accessible without authentication. It allows a remote attacker to retrieve sensitive configuration data, including the administrator web password, WiFi passphrase, and technical device information.This issue has been fixed in firmware version 1.1.0.651412
Title Config disclosure in T-Mobile 5G Box IDU routers
First Time appeared Wnc
Wnc t-mobile 5g Box Idu
Weaknesses CWE-306
CPEs cpe:2.3:a:wnc:t-mobile_5g_box_idu:*:*:*:*:*:*:*:*
Vendors & Products Wnc
Wnc t-mobile 5g Box Idu
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Wnc T-mobile 5g Box Idu
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-16T16:01:34.194Z

Reserved: 2026-04-15T11:10:34.850Z

Link: CVE-2026-40856

cve-icon Vulnrichment

Updated: 2026-09-16T16:01:29.263Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T12:17:03.790

Modified: 2026-09-28T23:10:00.143

Link: CVE-2026-40856

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:00:09Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function