Impact
An OS command injection flaw exists in the WNC T‑Mobile 5G Box IDU router, where the /cgi-bin/portal.cgi endpoint concatenates the cli_cookie POST parameter into a find command without validation. This allows a remote, unauthenticated attacker to inject and run arbitrary shell commands as root, giving full control over the underlying operating system.
Affected Systems
Devices running WNC T‑Mobile 5G Box IDU firmware versions older than 1.1.0.651412 are impacted; the vulnerability affects all units shipped with those firmware releases.
Risk and Exploitability
The CVSS rating of 9.4 indicates a critical severity. The EPSS score of 2% suggests a non‑negligible but moderate likelihood of exploitation. Based on the description, the likely attack vector is inferred to be remote and indiscriminate over the network, yet the device is not listed in the CISA KEV catalog. While no public exploit is documented, it is inferred that none are currently known. The high impact warrants rapid attention.
OpenCVE Enrichment