Vulnerability Description
WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value parameter, accepting any arbitrary value as valid. This allows a remote attacker to perform unauthorized actions on the device by tricking an authenticated user into visiting a malicious website.This issue has been fixed in firmware version 1.1.0.651412
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-40857?
CVE-2026-40857 is a documented vulnerability. WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value parameter, accepti...
How severe is CVE-2026-40857?
CVSS scoring is not yet available for CVE-2026-40857. Check NVD for updates.
Is there a patch for CVE-2026-40857?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.