VulnSea

WNC has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 9.0 (critical), with 3 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-78 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.0
Publish → KEV
Last 90 days
6 prev 0

Products

  • T-Mobile 5G Box IDU 6
6
Total CVEs
3
Critical
0
CISA KEV
0
Exploited

WNC vulnerabilities

CVEs affecting WNC, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-40854High· 8.7
6d ago

WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component

WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding fil…

TwilightWNC · T-Mobile 5G Box IDUEPSS 0.30%via NVD
CVE-2026-58146Critical· 9.4
6d ago

WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability

WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the /cgi-bin/portal.cgi endpoint, specifically through the cli_cookie POST parameter. The cli_cookie parameter value is d…

MidnightWNC · T-Mobile 5G Box IDUEPSS 2.1%via NVD
CVE-2026-40855Critical· 9.3
6d ago

WNC T-Mobile 5G Box IDU router is vulnerable to a command injection

WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality within the /cgi-bin/portal.cgi endpoint, specifically affecting the ping_ip, ping_size, and ping_times POST parameter…

MidnightWNC · T-Mobile 5G Box IDUEPSS 1.1%via NVD
CVE-2026-40857High· 8.4
6d ago

WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component

WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value parameter, accepting any arbitrary value as valid. This…

TwilightWNC · T-Mobile 5G Box IDUEPSS 0.19%via NVD
CVE-2026-40856High· 7.1
6d ago

WNC T-Mobile 5G Box IDU router is vulnerable to improper access control

WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgi endpoint, which is accessible without authentication. It allows a remote attacker to retrieve sensitive configurati…

TwilightWNC · T-Mobile 5G Box IDUEPSS 0.32%via NVD
CVE-2026-58147Critical· 9.3
6d ago

WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality

WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality. The application improperly neutralizes special elements in the http_passwd_hidden and http_passwdC…

MidnightWNC · T-Mobile 5G Box IDUEPSS 1.2%via NVD
WNC vulnerabilities (CVEs) · VulnSea