High severityNVD Advisory· Published Sep 16, 2026
CVE-2026-40856
CVE-2026-40856
Description
WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgi endpoint, which is accessible without authentication. It allows a remote attacker to retrieve sensitive configuration data, including the administrator web password, WiFi passphrase, and technical device information.This issue has been fixed in firmware version 1.1.0.651412
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: >=1.1.0.651412
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.