CVE-2026-40857
massCSRF in WNC T-Mobile 5G Box IDU Router Portal (portal.cgi)
The WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CWE-352) flaw in its portal.cgi component: the anti-CSRF mechanism fails to actually validate the csrf_token_value parameter, so any arbitrary token value is accepted as valid. An attacker exploits this by luring an already-authenticated user (e.g., someone logged into the router's admin portal) into visiting a malicious website, whose pages silently submit forged requests to the gateway over the local network. Because the CSRF check is effectively bypassed, the attacker can perform unauthorized actions on the device with the victim's session, such as changing device settings — reflected in the CVSS 4.0 score of 8.4 with high confidentiality and integrity impact and a requirement for user interaction. All users of this T-Mobile-branded router running firmware older than 1.1.0.651412 are affected. No exploitation has been reported in the wild, no public proof-of-concept is known, and the flaw is not listed in CISA's KEV catalog.
What to do: Upgrade the router to firmware version 1.1.0.651412 or later, available through the device's update mechanism or T-Mobile support. Until updated, avoid clicking links in unsolicited emails or websites while connected to the gateway's network, and review device settings (DNS servers, admin credentials, port forwarding) for unexpected changes.
| WNC (Wistron NeWeb Corporation) T-Mobile 5G Box IDU router (portal.cgi web portal) | All firmware versions prior to 1.1.0.651412 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value parameter, accepting any arbitrary value as valid. This allows a remote attacker to perform unauthorized actions on the device by tricking an authenticated user into visiting a malicious website.This issue has been fixed in firmware version 1.1.0.651412
- Weakness
- CWE-352
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.