Executive brief
The WNC T-Mobile 5G Box IDU router's web administration interface fails to properly validate anti-CSRF tokens, allowing an attacker to trick an authenticated administrator into performing unauthorized actions on the device via a malicious website. An attacker could modify router settings, change network configuration, or compromise connected devices without the administrator's knowledge or consent.
Technical details
This is a cross-site request forgery (CSRF) vulnerability in the portal.cgi component of the router's web interface. The anti-CSRF protection mechanism accepts any arbitrary value for the csrf_token_value parameter without proper validation, failing to prevent forged requests from untrusted origins. Attack requires an authenticated user (administrator) to be currently logged into the router and to visit an attacker-controlled website. An attacker can perform any action the logged-in user has permission to perform, such as modifying device configuration, updating settings, or creating new accounts. The vulnerability has been patched in firmware version 1.1.0.651412 and later.
Affected products
- WNC T-Mobile 5G Box IDU before 1.1.0.651412
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: firmware version 1.1.0.651412