OS Command Injection Vulnerability in WNC T-Mobile 5G Box IDU Router
CVE-2026-58147
9.3CRITICAL
What is CVE-2026-58147?
The WNC T-Mobile 5G Box IDU router is vulnerable to an OS command injection attack through the portal.cgi component's password change functionality. This vulnerability arises from the improper handling of inputs in the http_passwd_hidden and http_passwdConfirm_hidden parameters. An authenticated attacker could exploit this flaw to execute arbitrary commands on the router's operating system with root privileges. To mitigate this security risk, users are advised to update to firmware version 1.1.0.651412, where this vulnerability has been addressed.
Affected Version(s)
T-Mobile 5G Box IDU 0 < 1.1.0.651412
