Description
WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value parameter, accepting any arbitrary value as valid. This allows a remote attacker to perform unauthorized actions on the device by tricking an authenticated user into visiting a malicious website.This issue has been fixed in firmware version 1.1.0.651412
Published: 2026-09-16
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized privileged device actions
Action: Immediate Patch
AI Analysis

Impact

The T‑Mobile 5G Box IDU router’s portal.cgi component contains a CSRF flaw that accepts any csrf_token_value as valid, enabling a remote attacker to trick an authenticated user into executing arbitrary actions on the device. Because the anti‑CSRF check is bypassed, the attacker can perform any privileged operation that the user is authorized to do, potentially compromising device configuration and network operations.

Affected Systems

Affected devices are WNC T‑Mobile 5G Box IDU routers running firmware versions prior to 1.1.0.651412. The fix has been released in firmware 1.1.0.651412, which implements proper validation of the csrf_token_value parameter.

Risk and Exploitability

With a CVSS score of 8.4, the vulnerability is classified as high severity. The EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector is a remote web‑based CSRF attack that relies on social engineering to get an authenticated user to visit a malicious page; no local privileges or knowledge of credentials are required.

Generated by OpenCVE AI on September 18, 2026 at 02:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply firmware upgrade to version 1.1.0.651412 or later on all affected routers.
  • If an immediate firmware update is not feasible, disable the portal.cgi component or restrict web‑interface access to trusted IP addresses only.
  • Segment the network and limit administrative access to the router to reduce the impact of a compromised account.

Generated by OpenCVE AI on September 18, 2026 at 02:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value parameter, accepting any arbitrary value as valid. This allows a remote attacker to perform unauthorized actions on the device by tricking an authenticated user into visiting a malicious website.This issue has been fixed in firmware version 1.1.0.651412
Title CSRF token bypass in T-Mobile 5G Box IDU routers
First Time appeared Wnc
Wnc t-mobile 5g Box Idu
Weaknesses CWE-352
CPEs cpe:2.3:a:wnc:t-mobile_5g_box_idu:*:*:*:*:*:*:*:*
Vendors & Products Wnc
Wnc t-mobile 5g Box Idu
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Wnc T-mobile 5g Box Idu
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-16T16:00:47.111Z

Reserved: 2026-04-15T11:10:34.850Z

Link: CVE-2026-40857

cve-icon Vulnrichment

Updated: 2026-09-16T16:00:43.373Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T12:17:03.910

Modified: 2026-09-28T23:10:00.143

Link: CVE-2026-40857

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:00:09Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)