PT-2026-93696 · Wnc · T-Mobile 5G Box Idu

·

CVE-2026-40857

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

8.4

High

VectorAV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions WNC T-Mobile 5G Box IDU router versions prior to 1.1.0.651412
Description A cross-site request forgery (CSRF) issue exists in the 'portal.cgi' component. The anti-CSRF mechanism fails to validate the csrf token value parameter, accepting any arbitrary value as valid. This allows a remote attacker to perform unauthorized actions on the device by tricking an authenticated user into visiting a malicious website. CSRF is a type of attack that forces an authenticated user to execute unwanted actions on a web application in which they are currently authenticated.
Recommendations Update to firmware version 1.1.0.651412.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40857

Affected Products

T-Mobile 5G Box Idu