Beveiligingsadvies

CVE-2026-40856

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-16 11:21:13
Laatst bijgewerkt 2026-09-16 16:01:34
Toegewezen door CERT-PL
CVSS-score 7.1
Status PUBLISHED

Beschrijving

WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgi endpoint, which is accessible without authentication. It allows a remote attacker to retrieve sensitive configuration data, including the administrator web password, WiFi passphrase, and technical device information.This issue has been fixed in firmware version 1.1.0.651412