OS Command Injection Vulnerability in WNC T-Mobile 5G Box IDU Router
CVE-2026-58147

9.3CRITICAL

Key Information:

Vendor

Wnc

Vendor
CVE Published:
16 September 2026

What is CVE-2026-58147?

The WNC T-Mobile 5G Box IDU router is vulnerable to an OS command injection attack through the portal.cgi component's password change functionality. This vulnerability arises from the improper handling of inputs in the http_passwd_hidden and http_passwdConfirm_hidden parameters. An authenticated attacker could exploit this flaw to execute arbitrary commands on the router's operating system with root privileges. To mitigate this security risk, users are advised to update to firmware version 1.1.0.651412, where this vulnerability has been addressed.

Affected Version(s)

T-Mobile 5G Box IDU 0 < 1.1.0.651412

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Patryk Bogdan
Adam Borczyk
.