CERT Polska has disclosed six vulnerabilities affecting Wistron NeWeb Corporation (WNC) T-Mobile 5G Box IDU routers. The flaws comprise three critical and three high-severity issues, with the most serious, CVE-2026-58146, rated 9.4 under CVSSv4. The affected devices include all firmware versions before 1.1.0.651412. No active exploitation has been confirmed and no public proof-of-concept code is reportedly available.
The vulnerabilities include authentication bypass, command injection, cross-site request forgery and configuration disclosure. CVE-2026-40854 allows attackers to bypass session authentication by manipulating the `sessionid` cookie with directory-traversal characters, potentially exposing the administration panel. CVE-2026-58146 and CVE-2026-40855 can enable command injection through the `cli_cookie` parameter or ping functionality, with commands executed using root privileges.
CVE-2026-40856 may expose Wi-Fi passphrases and administrator passwords, while CVE-2026-58147 enables authorised remote code execution through the password-change function.
WNC has addressed the flaws in firmware version 1.1.0.651412. Device owners should contact their service provider to confirm that the update has been installed, particularly if firmware updates are not automatic. The article also recommends changing default passwords after updating.