Junglewise Threat Intelligence

CVE-2026-40857: WNC T-Mobile 5G Box IDU CSRF in portal.cgi

CVE-2026-40857 · Severity: info · Published 2026-09-16

Executive brief

The WNC T-Mobile 5G Box IDU router's web administration interface fails to properly validate anti-CSRF tokens, allowing an attacker to trick an authenticated administrator into performing unauthorized actions on the device via a malicious website. An attacker could modify router settings, change network configuration, or compromise connected devices without the administrator's knowledge or consent.

Technical details

This is a cross-site request forgery (CSRF) vulnerability in the portal.cgi component of the router's web interface. The anti-CSRF protection mechanism accepts any arbitrary value for the csrf_token_value parameter without proper validation, failing to prevent forged requests from untrusted origins. Attack requires an authenticated user (administrator) to be currently logged into the router and to visit an attacker-controlled website. An attacker can perform any action the logged-in user has permission to perform, such as modifying device configuration, updating settings, or creating new accounts. The vulnerability has been patched in firmware version 1.1.0.651412 and later.

Affected products

  • WNC T-Mobile 5G Box IDU before 1.1.0.651412

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: patched: firmware version 1.1.0.651412

References

Related threats