Executive brief
The WNC T-Mobile 5G Box IDU is a 5G router used by T-Mobile customers to provide home broadband connectivity. An authenticated attacker can inject arbitrary operating system commands through the password change functionality, gaining root access to the device and allowing them to modify settings, steal customer data, or disrupt service.
Technical details
This is an OS command injection vulnerability (CWE-78) in the portal.cgi component's password change functionality. The application fails to properly sanitize special shell characters in the http_passwd_hidden and http_passwdConfirm_hidden parameters before passing them to a system command. An authenticated attacker can exploit this to inject arbitrary shell commands and execute them with root privileges on the underlying Linux OS. The vulnerability requires authentication to exploit, and has been patched in firmware version 1.1.0.651412 and later.
Affected products
- WNC T-Mobile 5G Box IDU before 1.1.0.651412
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: Firmware version 1.1.0.651412