CVE-2026-58147 | WNC T-Mobile 5G Box IDU prior 1.1.0.651412 Password Change portal.cgi http_passwd_hidden/http_passwdConfirm_hidden os command injection
A vulnerability described as very critical has been identified in WNC T-Mobile 5G Box IDU. This affects an unknown part of the file portal.cgi of the component Password Change. Such manipulation of the argument http_passwd_hidden/http_passwdConfirm_hidden leads to os command injection.
This vulnerability is traded as CVE-2026-58147. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More