VORANT. Threat Intelligence Sign in Get the full feed

WNC T-Mobile 5G Box routers get root RCE flaws

routine vulnerability telecommunications

Six vulnerabilities in WNC T-Mobile 5G Box IDU routers allow unauthenticated attackers to bypass auth, steal credentials, and gain root via command injection.

CERT Polska coordinated disclosure of six vulnerabilities affecting WNC (Wistron NeWeb Corporation) T-Mobile 5G Box IDU routers. The flaws span authentication bypass, unauthenticated information disclosure, CSRF, and multiple OS command injection vulnerabilities in the portal.cgi and wnc_maccheck.cgi components. Most severe are CVE-2026-58146, which allows a remote, unauthenticated attacker to inject shell commands via the cli_cookie POST parameter and gain root access, and CVE-2026-40856, which exposes the admin web password, WiFi passphrase, and device configuration data without any authentication via the wnc_maccheck.cgi endpoint.

Additional issues include CVE-2026-40854, an authentication bypass in the session validation logic that trusts a sessionid cookie mapped to files in /tmp/login_user and can be manipulated using directory traversal sequences ("."/"..") to gain unauthorized admin panel access; CVE-2026-40855, a command injection in the ping diagnostic feature (ping_ip, ping_size, ping_times parameters) requiring authentication but yielding root shell access; CVE-2026-40857, a CSRF flaw where the anti-CSRF token is not properly validated, enabling attacker-controlled actions via a malicious webpage visited by an authenticated user; and CVE-2026-58147, an OS command injection in the password-change functionality via the http_passwd_hidden and http_passwdConfirm_hidden parameters, exploitable by an authenticated user for root-level command execution.

Chained together, an unauthenticated attacker could use CVE-2026-40856 or CVE-2026-40854 to obtain credentials or admin access, then leverage CVE-2026-58146, CVE-2026-40855, or CVE-2026-58147 for full root compromise of the device. All issues are fixed in firmware version 1.1.0.651412. Defenders operating these devices, likely deployed as consumer/SME 5G CPE by T-Mobile, should prioritize immediate firmware update and restrict management interface exposure to untrusted networks in the interim. No in-the-wild exploitation has been reported at time of disclosure.

Mentioned in this report

Vulnerabilities CVE-2026-40854CVE-2026-40855CVE-2026-40856CVE-2026-40857CVE-2026-58146CVE-2026-58147

Source reporting: https://cert.pl/en/posts/2026/09/CVE-2026-40854

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free