These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality. An authenticated attacker can execute arbitrary commands on the underlying operating system with root privileges due to improper neutralization of special elements in the http_passwd_hidden and http_passwdConfirm_hidden parameters. This issue has been fixed in firm [truncated]
A critical vulnerability exists in the WNC T-Mobile 5G Box IDU router, specifically within the /cgi-bin/portal.cgi endpoint through the cli_cookie POST parameter, allowing for OS command injection. This issue, tracked as CVE-2026-58146, enables a remote, unauthenticated attacker to execute arbitrary shell commands as root. The vulnerability has been fixed in firmware version 1.1.0.651412.
The WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value parameter, accepting any arbitrary value as valid. This allows a remote attacker to perform unauthorized actions on the device by tricking an authenticated user into visiting a malicious website. This issue has been fixed [truncated]
CVE-2026-40856 debrief: The WNC T-Mobile 5G Box IDU router has a vulnerability in the wnc_maccheck.cgi endpoint, allowing unauthorized access to sensitive configuration data, including administrator web password, WiFi passphrase, and technical device information. This issue has been fixed in firmware version 1.1.0.651412. Defenders should assess exposure and prioritize upgrading to the fixed firmware vers [truncated]
The WNC T-Mobile 5G Box IDU router has a critical vulnerability (CVE-2026-40855, CVSS score 9.3) allowing authenticated attackers to execute arbitrary commands as root via the /cgi-bin/portal.cgi endpoint's ping functionality. This issue, caused by insufficient input sanitization, was fixed in firmware version 1.1.0.651412. System administrators and security teams should assess exposure, prioritize verifi [truncated]
The WNC T-Mobile 5G Box IDU router has an authentication bypass vulnerability in the portal.cgi component. An attacker can bypass authentication by manipulating the sessionid cookie, allowing unauthorized access to the administration panel. This issue has been fixed in firmware version 1.1.0.651412. The vulnerability allows an attacker to access the administration panel without proper authentication, pote [truncated]