ZeroHour

CVE-2026-40857

mass

CSRF in WNC T-Mobile 5G Box IDU Router Portal (portal.cgi)

CVSS 4.0
8.4 high
EPSS
Published
()
Modified
AI analysis

The WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CWE-352) flaw in its portal.cgi component: the anti-CSRF mechanism fails to actually validate the csrf_token_value parameter, so any arbitrary token value is accepted as valid. An attacker exploits this by luring an already-authenticated user (e.g., someone logged into the router's admin portal) into visiting a malicious website, whose pages silently submit forged requests to the gateway over the local network. Because the CSRF check is effectively bypassed, the attacker can perform unauthorized actions on the device with the victim's session, such as changing device settings — reflected in the CVSS 4.0 score of 8.4 with high confidentiality and integrity impact and a requirement for user interaction. All users of this T-Mobile-branded router running firmware older than 1.1.0.651412 are affected. No exploitation has been reported in the wild, no public proof-of-concept is known, and the flaw is not listed in CISA's KEV catalog.

What to do: Upgrade the router to firmware version 1.1.0.651412 or later, available through the device's update mechanism or T-Mobile support. Until updated, avoid clicking links in unsolicited emails or websites while connected to the gateway's network, and review device settings (DNS servers, admin credentials, port forwarding) for unexpected changes.

Affected
WNC (Wistron NeWeb Corporation) T-Mobile 5G Box IDU router (portal.cgi web portal)All firmware versions prior to 1.1.0.651412
Estimated exposure
masslikely hundreds of thousands to millions of deployed home gateways (T-Mobile-branded consumer 5G router) — This WNC-manufactured gateway is distributed by T-Mobile to home-internet subscribers, a customer base in the millions, though model-level install counts are not published so the exact figure is an order-of-magnitude estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value parameter, accepting any arbitrary value as valid. This allows a remote attacker to perform unauthorized actions on the device by tricking an authenticated user into visiting a malicious website.This issue has been fixed in firmware version 1.1.0.651412

Weakness
CWE-352
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.