CVE-2026-40854: Session auth bypass via cookie value in T-Mobile 5G Box IDU routers
WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding file in /tmp/loginuser. An attacker can bypass authentication by using directory entries such as "." or ".." in the cookie, allowing unauthorized access to the administration panel.This issue has been fixed in firmware version 1.1.0.651412
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WNC T-Mobile 5G Box IDU routers (portal.cgi)to a version that resolves this vulnerability.Fixed in 1.1.0.651412
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker needs to be able to send requests to the router's portal.cgi interface and control the sessionid cookie value. Using directory entries such as "." or ".." as the cookie value can bypass the session check.
Does exploitation require valid router credentials or an existing session?
No. The flaw bypasses authentication because the session validation checks only whether a corresponding path exists under /tmp/login_user; directory entries can satisfy that check without a legitimate session.
Which firmware version fixes the vulnerability?
The issue is fixed in firmware version 1.1.0.651412.