CVE-2026-40855

WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality within the /cgi-bin/portal.cgi endpoint, specifically affecting the ping_ip, ping_size, and ping_times POST parameters. The root cause is the failure to verify and sanitize user-supplied input before incorporating it into a system command. This allows an authenticated attacker to execute arbitrary commands on the shell and gain root access to the system.This issue has been fixed in firmware versionĀ 1.1.0.651412
CVSS

No CVSS.

Configurations

No configuration.

History

16 Sep 2026, 12:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-16 12:17

Updated : 2026-09-16 12:17


NVD link : CVE-2026-40855

Mitre link : CVE-2026-40855

CVE.ORG link : CVE-2026-40855


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')