Executive brief
The WNC T-Mobile 5G Box IDU is a wireless router used by T-Mobile customers to provide 5G connectivity. A vulnerability in the wnc_maccheck.cgi endpoint allows an unauthenticated remote attacker to retrieve sensitive configuration data, including administrator passwords, WiFi passphrases, and device technical information. This could lead to unauthorized access to the router's administrative panel and WiFi network compromise.
Technical details
The vulnerability is a missing authentication for critical function (CWE-306) in the wnc_maccheck.cgi endpoint of WNC T-Mobile 5G Box IDU firmware. The endpoint is accessible without any authentication mechanism and exposes sensitive configuration data via unauthenticated requests. A remote attacker on the network can directly query this endpoint to retrieve administrative credentials, WiFi passphrases, and device configuration information. The attack requires network reachability to the router but no prior authentication or credentials. This issue has been patched in firmware version 1.1.0.651412 and earlier versions are vulnerable.
Affected products
- WNC T-Mobile 5G Box IDU before 1.1.0.651412
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: Fixed in firmware version 1.1.0.651412