Executive brief
The WNC T-Mobile 5G Box IDU is a 5G router device used by T-Mobile customers to provide broadband connectivity. The ping function in the router's web interface fails to validate user input, allowing an authenticated attacker to inject and execute arbitrary shell commands with root privileges, potentially compromising the device and any network it protects.
Technical details
This is an OS command injection vulnerability (CWE-78) in the /cgi-bin/portal.cgi endpoint, specifically affecting the ping_ip, ping_size, and ping_times POST parameters. The root cause is insufficient input validation and sanitization before these parameters are passed to system commands. An authenticated attacker can inject shell metacharacters to break out of the intended command and execute arbitrary commands with root privileges. The vulnerability requires authentication to exploit but allows full system compromise. The vendor released firmware version 1.1.0.651412 to address this issue.
Affected products
- WNC T-Mobile 5G Box IDU all versions before 1.1.0.651412
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: firmware version 1.1.0.651412 released