---
id: CVE-2026-40854
title: >-
  WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability
  in the portal.cgi component
summary: >-
  WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability
  in the portal.cgi component. The session verification mechanism improperly
  validates the sessionid cookie by checking for the existence of a
  corresponding fil…
severity: high
cvss: 8.7
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-290
vendor: WNC
product: T-Mobile 5G Box IDU
affected:
  - t-mobile_5g_box_idu < 1.1.0.651412
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:14:25.980'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-40854'
references:
  - url: 'https://cert.pl/posts/2026/09/CVE-2026-40854'
    label: cvd@cert.pl
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-16T17:40:01.238581Z'
cvssSource: cna
ingestedAt: '2026-09-16T11:54:38.962Z'
epss: 0.00319
epssPercentile: 0.22217
---

## Overview

WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding file in /tmp/login_user. An attacker can bypass authentication by using directory entries such as "." or ".." in the cookie, allowing unauthorized access to the administration panel.This issue has been fixed in firmware version 1.1.0.651412

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
