CERT Polska disclosed six vulnerabilities in WNC (Wistron NeWeb Corporation) T-Mobile 5G Box IDU router firmware versions earlier than 1.1.0.651412: CVE-2026-58146, CVE-2026-58147, and CVE-2026-40854 through CVE-2026-40857. The issues include an authentication bypass, three OS command-injection flaws, unauthenticated information disclosure, and CSRF; affected devices may expose sensitive configuration data, including administrator credentials and Wi-Fi passphrases, or permit remote shell-command execution as root.
CVE-2026-40854 abuses session validation in portal.cgi, where crafted sessionid cookie values such as directory references can bypass access controls and reach the administration panel (CVSS 8.7). CVE-2026-40855 affects the portal.cgi ping function: insufficient validation of ping_ip, ping_size, and ping_times permits an authenticated attacker to inject shell commands as root (CVSS 9.3). WNC has addressed all six flaws in firmware 1.1.0.651412; organizations operating these routers should identify devices and upgrade promptly.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
CERT Polska published six CVEs affecting T-Mobile 5G Box IDU firmware earlier than 1.1.0.651412, including an authentication bypass, three root-level command-injection flaws, unauthenticated configuration disclosure, and CSRF. WNC fixed all six issues in firmware version 1.1.0.651412.
CERT Polska received a report concerning six vulnerabilities in WNC T-Mobile 5G Box IDU router firmware: CVE-2026-40854 through CVE-2026-40857, CVE-2026-58146, and CVE-2026-58147.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cert.pl
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.