Description
WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the /cgi-bin/portal.cgi endpoint, specifically through the cli_cookie POST parameter. The cli_cookie parameter value is directly concatenated into a find command string without proper sanitization. This allows a remote, unauthenticated attacker to inject and execute arbitrary shell commands as root on the underlying operating system.

This issue has been fixed in firmware version 1.1.0.651412
Published: 2026-09-16
Score: 9.4 Critical
EPSS: 2.9% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An OS command injection flaw exists in the WNC T‑Mobile 5G Box IDU router, where the /cgi-bin/portal.cgi endpoint concatenates the cli_cookie POST parameter into a find command without validation. This allows a remote, unauthenticated attacker to inject and run arbitrary shell commands as root, giving full control over the underlying operating system.

Affected Systems

Devices running WNC T‑Mobile 5G Box IDU firmware versions older than 1.1.0.651412 are impacted; the vulnerability affects all units shipped with those firmware releases.

Risk and Exploitability

The CVSS rating of 9.4 indicates a critical severity. The EPSS score of 2% suggests a non‑negligible but moderate likelihood of exploitation. Based on the description, the likely attack vector is inferred to be remote and indiscriminate over the network, yet the device is not listed in the CISA KEV catalog. While no public exploit is documented, it is inferred that none are currently known. The high impact warrants rapid attention.

Generated by OpenCVE AI on September 18, 2026 at 03:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the router firmware to version 1.1.0.651412 or later.
  • If a firmware update cannot be applied immediately, block external access to the /cgi-bin/portal.cgi endpoint using firewall or ACL rules.
  • Enable comprehensive logging and monitor for abnormal command execution attempts on the device.

Generated by OpenCVE AI on September 18, 2026 at 03:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the /cgi-bin/portal.cgi endpoint, specifically through the cli_cookie POST parameter. The cli_cookie parameter value is directly concatenated into a find command string without proper sanitization. This allows a remote, unauthenticated attacker to inject and execute arbitrary shell commands as root on the underlying operating system. This issue has been fixed in firmware version 1.1.0.651412
Title Unauthorized remote code execution in T-Mobile 5G Box IDU routers
First Time appeared Wnc
Wnc t-mobile 5g Box Idu
Weaknesses CWE-78
CPEs cpe:2.3:a:wnc:t-mobile_5g_box_idu:*:*:*:*:*:*:*:*
Vendors & Products Wnc
Wnc t-mobile 5g Box Idu
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Wnc T-mobile 5g Box Idu
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-16T15:58:50.554Z

Reserved: 2026-06-29T14:19:37.080Z

Link: CVE-2026-58146

cve-icon Vulnrichment

Updated: 2026-09-16T15:58:47.776Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T12:17:04.980

Modified: 2026-09-28T23:10:00.143

Link: CVE-2026-58146

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:30:02Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')