Description
WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality. The application improperly neutralizes special elements in the http_passwd_hidden and http_passwdConfirm_hidden parameters, allowing an authenticated attacker to execute arbitrary commands on the underlying operating system with root privileges.This issue has been fixed in firmware version 1.1.0.651412
Published: 2026-09-16
Score: 9.3 Critical
EPSS: 1.6% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an authenticated attacker to execute arbitrary operating system commands with root privileges by manipulating the http_passwd_hidden and http_passwdConfirm_hidden fields in the password change component. Because the application fails to neutralize special characters, the attacker can inject OS commands, leading to complete system compromise. The weakness is a command injection (CWE-78) and it directly impacts confidentiality, integrity, and availability.

Affected Systems

The affected device is the WNC T‑Mobile 5G Box IDU router. Firmware prior to 1.1.0.651412 is vulnerable. The fix is available in firmware 1.1.0.651412 and later.

Risk and Exploitability

With a CVSS score of 9.3 and an EPSS score of 1 %, the risk is high. The exploit requires authenticated access to the router’s management interface, but once reached, it provides root-level execution. The vulnerability is not listed in the CISA KEV catalog, although the exploit probability is non‑zero.

Generated by OpenCVE AI on September 18, 2026 at 02:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply firmware update 1.1.0.651412 or later to remove the command injection flaw.
  • Restrict access to the router’s management interface and password change function to trusted networks and authenticated users only.
  • Monitor device logs for abnormal command strings or attempts to inject payloads via the password change parameters.

Generated by OpenCVE AI on September 18, 2026 at 02:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality. The application improperly neutralizes special elements in the http_passwd_hidden and http_passwdConfirm_hidden parameters, allowing an authenticated attacker to execute arbitrary commands on the underlying operating system with root privileges.This issue has been fixed in firmware version 1.1.0.651412
Title Authorized remote code execution via password change functionality in T-Mobile 5G Box IDU routers
First Time appeared Wnc
Wnc t-mobile 5g Box Idu
Weaknesses CWE-78
CPEs cpe:2.3:a:wnc:t-mobile_5g_box_idu:*:*:*:*:*:*:*:*
Vendors & Products Wnc
Wnc t-mobile 5g Box Idu
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Wnc T-mobile 5g Box Idu
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-16T15:58:25.276Z

Reserved: 2026-06-29T14:19:37.080Z

Link: CVE-2026-58147

cve-icon Vulnrichment

Updated: 2026-09-16T15:53:13.368Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T12:17:05.103

Modified: 2026-09-28T23:10:00.143

Link: CVE-2026-58147

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:00:09Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')