CVE-2026-58146: Unauthorized remote code execution in T-Mobile 5G Box IDU routers
WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the /cgi-bin/portal.cgi endpoint, specifically through the clicookie POST parameter. The clicookie parameter value is directly concatenated into a find command string without proper sanitization. This allows a remote, unauthenticated attacker to inject and execute arbitrary shell commands as root on the underlying operating system.
This issue has been fixed in firmware version 1.1.0.651412
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WNC T-Mobile 5G Box IDU router firmware (/cgi-bin/portal.cgi, cli_cookie POST parameter)to a version that resolves this vulnerability.Fixed in 1.1.0.651412
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote, unauthenticated attacker can exploit it. No login or prior access is described as necessary.
What access does successful exploitation provide?
An attacker can inject arbitrary shell commands through the cli_cookie POST parameter at /cgi-bin/portal.cgi. The commands execute as root on the router's underlying operating system.
Which firmware version contains the fix?
The issue is fixed in firmware version 1.1.0.651412.