NONE · 0

CVE-2026-40857

WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value parameter, accepti...

Vulnerability Description

WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value parameter, accepting any arbitrary value as valid. This allows a remote attacker to perform unauthorized actions on the device by tricking an authenticated user into visiting a malicious website.This issue has been fixed in firmware version 1.1.0.651412

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-40857?

CVE-2026-40857 is a documented vulnerability. WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value parameter, accepti...

How severe is CVE-2026-40857?

CVSS scoring is not yet available for CVE-2026-40857. Check NVD for updates.

Is there a patch for CVE-2026-40857?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.