PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-58146 WNC CVE debrief

A critical vulnerability exists in the WNC T-Mobile 5G Box IDU router, specifically within the /cgi-bin/portal.cgi endpoint through the cli_cookie POST parameter, allowing for OS command injection. This issue, tracked as CVE-2026-58146, enables a remote, unauthenticated attacker to execute arbitrary shell commands as root. The vulnerability has been fixed in firmware version 1.1.0.651412.

Vendor
WNC
Product
T-Mobile 5G Box IDU
CVSS
CRITICAL 9.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-09-28
Advisory published
2026-09-16
Advisory updated
2026-09-28

Who should care

Network administrators and security teams responsible for WNC T-Mobile 5G Box IDU routers should assess exposure and take remediation steps. This includes verifying the current firmware version, upgrading to firmware version 1.1.0.651412 or later, and enhancing monitoring and incident response plans. Additionally, operators and platform administrators should review compensating controls for exposed systems and implement additional security measures such as

Why it matters

CVE-2026-58146 is a critical OS command injection vulnerability in the WNC T-Mobile 5G Box IDU router that allows remote, unauthenticated attackers to execute arbitrary shell commands as root. Network administrators and security teams should verify exposure, upgrade to firmware version 1.1.0.651412 or later, and enhance monitoring and incident response plans.

  • Remote code execution as root on affected devices
  • Potential for lateral movement within networks
  • Need for immediate firmware updates
  • Verification of network traffic monitoring and incident response plans

Technical summary

The WNC T-Mobile 5G Box IDU router is vulnerable to an OS command injection attack through the cli_cookie POST parameter in the /cgi-bin/portal.cgi endpoint. This allows a remote, unauthenticated attacker to execute arbitrary shell commands as root on the underlying operating system. The issue has been addressed in firmware version 1.1.0.651412. Affected product deployments should be verified for exposure, and immediate upgrading to firmware version 1.1.0.651412 or later is recommended. Network administrators and security teams should also enhance monitoring and incident response plans to address potential impacts.

Defensive priority

Immediate verification of exposure and upgrading to firmware version 1.1.0.651412 or later is recommended for WNC T-Mobile 5G Box IDU router users.

Recommended defensive actions

  • Verify exposure by checking the current firmware version of WNC T-Mobile 5G Box IDU routers
  • Upgrade to firmware version 1.1.0.651412 or later
  • Monitor network traffic to /cgi-bin/portal.cgi for suspicious activity
  • Implement additional security measures such as network segmentation and access controls
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, including its existence within the /cgi-bin/portal.cgi endpoint and the availability of a fix in firmware version 1.1.0.651412.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-58146 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-58146

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-58146 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58146

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.