Executive brief
The WNC T-Mobile 5G Box IDU is a 5G wireless router used by T-Mobile customers to provide home internet service. This vulnerability allows attackers to bypass login authentication by exploiting a flaw in how the router validates user session cookies, potentially granting unauthorized access to the administrative control panel and sensitive network configuration settings.
Technical details
CVE-2026-40854 is an authentication bypass vulnerability in the portal.cgi component of the WNC T-Mobile 5G Box IDU router. The session verification mechanism fails to properly validate the sessionid cookie; it only checks for the existence of a corresponding file in /tmp/login_user, allowing attackers to bypass authentication by injecting directory traversal sequences (e.g., "." or "..") into the cookie value. No authentication is required—the attack is network-accessible. A successful exploit grants an unauthenticated attacker full access to the device's administrative panel and configuration. The vulnerability was fixed in firmware version 1.1.0.651412.
Affected products
- WNC T-Mobile 5G Box IDU All versions before 1.1.0.651412
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: Fixed in firmware version 1.1.0.651412