Junglewise Threat Intelligence

CVE-2026-58147: WNC T-Mobile 5G Box IDU OS command injection in password change

CVE-2026-58147 · Severity: info · Published 2026-09-16

Executive brief

The WNC T-Mobile 5G Box IDU is a 5G router used by T-Mobile customers to provide home broadband connectivity. An authenticated attacker can inject arbitrary operating system commands through the password change functionality, gaining root access to the device and allowing them to modify settings, steal customer data, or disrupt service.

Technical details

This is an OS command injection vulnerability (CWE-78) in the portal.cgi component's password change functionality. The application fails to properly sanitize special shell characters in the http_passwd_hidden and http_passwdConfirm_hidden parameters before passing them to a system command. An authenticated attacker can exploit this to inject arbitrary shell commands and execute them with root privileges on the underlying Linux OS. The vulnerability requires authentication to exploit, and has been patched in firmware version 1.1.0.651412 and later.

Affected products

  • WNC T-Mobile 5G Box IDU before 1.1.0.651412

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: patched: Firmware version 1.1.0.651412

References

Related threats