VYPR

T-Mobile 5G Box IDU router

by WNC

CVEs (6)

  • CVE-2026-58146CriSep 16, 2026
    risk 0.61cvss epss

    WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the /cgi-bin/portal.cgi endpoint, specifically through the cli_cookie POST parameter. The cli_cookie parameter value is directly concatenated into a find command…

  • CVE-2026-58147CriSep 16, 2026
    risk 0.60cvss epss

    WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality. The application improperly neutralizes special elements in the http_passwd_hidden and http_passwdConfirm_hidden parameters, allowing an…

  • CVE-2026-40855CriSep 16, 2026
    risk 0.60cvss epss

    WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality within the /cgi-bin/portal.cgi endpoint, specifically affecting the ping_ip, ping_size, and ping_times POST parameters. The root cause is the failure to verify…

  • CVE-2026-40854HigSep 16, 2026
    risk 0.57cvss epss

    WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding file in /tmp/login_user. An attacker can…

  • CVE-2026-40857HigSep 16, 2026
    risk 0.55cvss epss

    WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value parameter, accepting any arbitrary value as valid. This allows a remote attacker to perform…

  • CVE-2026-40856HigSep 16, 2026
    risk 0.46cvss epss

    WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgi endpoint, which is accessible without authentication. It allows a remote attacker to retrieve sensitive configuration data, including the administrator web…