Impact
The T‑Mobile 5G Box IDU router’s portal.cgi component contains a CSRF flaw that accepts any csrf_token_value as valid, enabling a remote attacker to trick an authenticated user into executing arbitrary actions on the device. Because the anti‑CSRF check is bypassed, the attacker can perform any privileged operation that the user is authorized to do, potentially compromising device configuration and network operations.
Affected Systems
Affected devices are WNC T‑Mobile 5G Box IDU routers running firmware versions prior to 1.1.0.651412. The fix has been released in firmware 1.1.0.651412, which implements proper validation of the csrf_token_value parameter.
Risk and Exploitability
With a CVSS score of 8.4, the vulnerability is classified as high severity. The EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector is a remote web‑based CSRF attack that relies on social engineering to get an authenticated user to visit a malicious page; no local privileges or knowledge of credentials are required.
OpenCVE Enrichment