OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-58146

CRITICAL · CVSS 9.4 EPSS 2.89%

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The WNC T-Mobile 5G Box IDU router is susceptible to an OS command injection vulnerability via the /cgi-bin/portal.cgi endpoint, where the cli_cookie POST parameter is improperly sanitized. This flaw enables remote, unauthenticated attackers to execute arbitrary shell commands with root privileges, posing a critical security risk. Organizations using this router should prioritize applying the firmware update to version 1.1.0.651412 to mitigate potential exploitation.

CVE
CVE-2026-58146
Severity
CRITICAL
CVSS
9.4
EPSS
2.89%

Original NVD Description

WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the /cgi-bin/portal.cgi endpoint, specifically through the cli_cookie POST parameter. The cli_cookie parameter value is directly concatenated into a find command string without proper sanitization. This allows a remote, unauthenticated attacker to inject and execute arbitrary shell commands as root on the underlying operating system. This issue has been fixed in firmware versionĀ 1.1.0.651412