CVE-2026-40857

WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value parameter, accepting any arbitrary value as valid. This allows a remote attacker to perform unauthorized actions on the device by tricking an authenticated user into visiting a malicious website.This issue has been fixed in firmware versionĀ 1.1.0.651412
CVSS

No CVSS.

Configurations

No configuration.

History

16 Sep 2026, 12:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-16 12:17

Updated : 2026-09-16 12:17


NVD link : CVE-2026-40857

Mitre link : CVE-2026-40857

CVE.ORG link : CVE-2026-40857


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)