CVE-2026-58147 is an OS command injection vulnerability in the web-management password-change functionality of WNC T-Mobile 5G Box IDU routers running firmware earlier than 1.1.0.651412. The application fails to properly neutralize shell-special elements supplied through the http_passwd_hidden and http_passwdConfirm_hidden parameters. An authenticated attacker can inject operating-system commands that execute with root privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authenticated OS command-injection vulnerability in the portal.cgi password-change functionality of WNC T-Mobile 5G Box IDU routers. Crafted password-related parameters enable arbitrary root-level command execution.
A critical authenticated OS command-injection vulnerability in the WNC T-Mobile 5G Box IDU router's portal.cgi password-change function. Successful exploitation permits arbitrary command execution as root.
A reported vulnerability in the firmware of WNC T-Mobile 5G Box IDU routers; no technical details are provided.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.