Junglewise Threat Intelligence

CVE-2026-40854: WNC T-Mobile 5G Box IDU authentication bypass in portal.cgi

CVE-2026-40854 · Severity: info · CVSS 7.5 · Published 2026-09-16

Executive brief

The WNC T-Mobile 5G Box IDU is a 5G wireless router used by T-Mobile customers to provide home internet service. This vulnerability allows attackers to bypass login authentication by exploiting a flaw in how the router validates user session cookies, potentially granting unauthorized access to the administrative control panel and sensitive network configuration settings.

Technical details

CVE-2026-40854 is an authentication bypass vulnerability in the portal.cgi component of the WNC T-Mobile 5G Box IDU router. The session verification mechanism fails to properly validate the sessionid cookie; it only checks for the existence of a corresponding file in /tmp/login_user, allowing attackers to bypass authentication by injecting directory traversal sequences (e.g., "." or "..") into the cookie value. No authentication is required—the attack is network-accessible. A successful exploit grants an unauthenticated attacker full access to the device's administrative panel and configuration. The vulnerability was fixed in firmware version 1.1.0.651412.

Affected products

  • WNC T-Mobile 5G Box IDU All versions before 1.1.0.651412

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: patched: Fixed in firmware version 1.1.0.651412

References

Related threats