Impact
The vulnerability allows an authenticated attacker to execute arbitrary operating system commands with root privileges by manipulating the http_passwd_hidden and http_passwdConfirm_hidden fields in the password change component. Because the application fails to neutralize special characters, the attacker can inject OS commands, leading to complete system compromise. The weakness is a command injection (CWE-78) and it directly impacts confidentiality, integrity, and availability.
Affected Systems
The affected device is the WNC T‑Mobile 5G Box IDU router. Firmware prior to 1.1.0.651412 is vulnerable. The fix is available in firmware 1.1.0.651412 and later.
Risk and Exploitability
With a CVSS score of 9.3 and an EPSS score of 1 %, the risk is high. The exploit requires authenticated access to the router’s management interface, but once reached, it provides root-level execution. The vulnerability is not listed in the CISA KEV catalog, although the exploit probability is non‑zero.
OpenCVE Enrichment