Impact
The vulnerable endpoint wnc_maccheck.cgi allows any network host to retrieve the router's configuration without authentication, exposing administrator credentials, Wi‑Fi keys and other device parameters. This improper access control flaw, classified as CWE‑306, means that a remote attacker can read confidential settings that should be restricted to privileged users. The immediate result is full visibility into the device's administrative secrets and wireless network details.
Affected Systems
This flaw affects WNC's T‑Mobile 5G Box IDU routers. The vulnerability is present in firmware versions earlier than 1.1.0.651412, the patch that addresses the issue. No other vendors or product lines are cited.
Risk and Exploitability
The CVSS score of 7.1 signifies a moderate to high severity, while the EPSS score of less than 1 % indicates that exploit likelihood is currently very low. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known widespread exploitation. Attackers could remotely trigger the CGI endpoint over the WAN or LAN ports and obtain sensitive configuration files, potentially enabling further lateral movement or credential-based attacks. Because the vulnerability requires only unauthenticated access to the HTTP interface, anyone with network reach can exploit it.
OpenCVE Enrichment