CVE-2026-40856 - Config disclosure in T-Mobile 5G Box IDU routers
CVE ID :CVE-2026-40856
Published : Sept. 16, 2026, 12:17 p.m. | 51 minutes ago
Description :WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgi endpoint, which is accessible without authentication. It allows a remote attacker to retrieve sensitive configuration data, including the administrator web password, WiFi passphrase, and technical device information.This issue has been fixed in firmware version 1.1.0.651412
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 16, 2026, 12:17 p.m. | 51 minutes ago
Description :WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgi endpoint, which is accessible without authentication. It allows a remote attacker to retrieve sensitive configuration data, including the administrator web password, WiFi passphrase, and technical device information.This issue has been fixed in firmware version 1.1.0.651412
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...