PatchSiren cyber security CVE debrief
CVE-2026-40855 WNC CVE debrief
The WNC T-Mobile 5G Box IDU router has a critical vulnerability (CVE-2026-40855, CVSS score 9.3) allowing authenticated attackers to execute arbitrary commands as root via the /cgi-bin/portal.cgi endpoint's ping functionality. This issue, caused by insufficient input sanitization, was fixed in firmware version 1.1.0.651412. System administrators and security teams should assess exposure, prioritize verification of affected systems, and apply the firmware update.
- Vendor
- WNC
- Product
- T-Mobile 5G Box IDU
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-09-28
Who should care
System administrators and security teams responsible for WNC T-Mobile 5G Box IDU routers should assess exposure and prioritize verification and remediation. They must verify if systems are running firmware version 1.1.0.651412 or later and apply the firmware update if vulnerable. Additionally, they should monitor system logs for suspicious activity and review compensating controls for exposed systems while remediation is scheduled and verified.
Why it matters
CVE-2026-40855 is a critical vulnerability in the WNC T-Mobile 5G Box IDU router, allowing authenticated command injection. System administrators and security teams must assess exposure, prioritize verification, and apply the firmware update to prevent exploitation.
- Authenticated attackers can execute arbitrary commands as root
- Potential for lateral movement and further exploitation
- Need for immediate firmware update and system verification
- Possible impact on network integrity and data confidentiality
Technical summary
The WNC T-Mobile 5G Box IDU router's /cgi-bin/portal.cgi endpoint is vulnerable to command injection via the ping_ip, ping_size, and ping_times POST parameters. An authenticated attacker can execute arbitrary commands as root due to insufficient input sanitization. This issue has been fixed in firmware version 1.1.0.651412. System administrators and security teams should assess exposure, prioritize verification of affected systems, and apply the firmware update to prevent exploitation. The vulnerability has a CVSS score of 9.3, indicating a critical severity level.
Defensive priority
High
Recommended defensive actions
- Assess exposure of WNC T-Mobile 5G Box IDU routers in your environment
- Verify if systems are running firmware version 1.1.0.651412 or later
- Apply the firmware update if vulnerable
- Monitor system logs for suspicious activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and the affected product. However, the vendor and product names are not specified, which may limit the scope of affected systems.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-40855 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-40855
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-40855 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40855
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cert.pl/posts/2026/09/CVE-2026-40854
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.