Security researchers at CERT Polska disclosed several critical T-Mobile 5G Box vulnerabilities. These severe software flaws impact Wistron NeWeb Corporation (WNC) routers. Hackers can exploit these bugs to bypass authentication entirely. They can also execute malicious system commands. Administrators must patch their routers immediately to stop unauthorized access.
- Total: 6 CVEs
- Severity: 3 Critical · 3 High
- Actively exploited: None confirmed
- Highest severity: 9.4 (Critical · CVSSv4) — CVE-2026-58146
- Action: Apply the latest security updates now
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsNotable CVEs
| CVE | CVSS (CVSSv4) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-58146 | 9.4 | Unauthorized remote code execution in routers | 1.1.0.651412 | Not exploited |
| CVE-2026-40855 | 9.3 | Command Injection in router via ping functionality | 1.1.0.651412 | Not exploited |
| CVE-2026-58147 | 9.3 | Authorized remote code execution via password change functionality in routers | 1.1.0.651412 | Not exploited |
| CVE-2026-40854 | 8.7 | Session auth bypass via cookie value in routers | 1.1.0.651412 | Not exploited |
| CVE-2026-40857 | 8.4 | CSRF token bypass in routers | 1.1.0.651412 | Not exploited |
| CVE-2026-40856 | 7.1 | Config disclosure in routers | 1.1.0.651412 | Not exploited |
Why This Matters
Internet service providers distribute these 5G routers to thousands of residential and business customers. Consequently, unpatched T-Mobile 5G Box vulnerabilities expose home networks and corporate data to severe risks. If attackers hijack a router, they can spy on local network traffic. Furthermore, intruders can use compromised devices to launch massive attacks against other targets.
How the Attack Works
These T-Mobile 5G Box vulnerabilities span multiple authentication and injection flaws. For instance, CVE-2026-40854 enables an authentication bypass. The session verification mechanism improperly validates cookies. Attackers manipulate the sessionid cookie using directory traversal characters. This action grants them full access to the administration panel.
Additionally, CVE-2026-58146 and CVE-2026-40855 introduce critical command injection weaknesses. Attackers inject shell commands through the cli_cookie parameter or the ping functionality. The router executes these unverified inputs with root privileges. Furthermore, CVE-2026-40856 allows unauthorized users to steal Wi-Fi passphrases and admin passwords. Another flaw, CVE-2026-40857, permits cross-site request forgery attacks. Currently, researchers have confirmed no active in-the-wild exploitation. Likewise, no public proof-of-concept exploit code exists.
Affected Versions
These defects affect WNC T-Mobile 5G Box IDU routers. Specifically, the bugs exist in all firmware versions prior to 1.1.0.651412. Many users might run older software without realizing their exposure.
Patch and Mitigation Steps
Users must update their hardware immediately to secure their networks. WNC resolved these flaws in firmware version 1.1.0.651412. Device owners should contact their service provider to ensure their routers receive the latest firmware automatically. Administrators should also change default passwords.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!