CRITICAL 9.4 NVD
CVE-2026-58146
WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the /cgi-bin/portal.cgi endpoint, specifical
WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the /cgi-bin/portal.cgi endpoint, specifically through the cli_cookie POST parameter. The cli_cookie parameter value is directly concatenated into a find command string without proper sanitization. This allows a remote, unauthenticated attacker to inject and execute arbitrary shell commands as root on the underlying operating system.
This issue has been fixed in firmware version 1.1.0.651412
References
This critical severity vulnerability with a CVSS score of 9.4 was published on 2026-09-16 via NVD.
Risk Timeline
CVE Disclosed2026-09-16 · -1 days ago
Remediation Resources
Official Advisory
cert.pl/posts/2026/09/CVE-2026-40854
vulnfeed aggregates 14391 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.