CVE-2026-40857: CSRF token bypass in T-Mobile 5G Box IDU routers
WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrftokenvalue parameter, accepting any arbitrary value as valid. This allows a remote attacker to perform unauthorized actions on the device by tricking an authenticated user into visiting a malicious website.This issue has been fixed in firmware version 1.1.0.651412
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
T-Mobile 5G Box IDU router (portal.cgi)to a version that resolves this vulnerability.Fixed in 1.1.0.651412
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker needs to trick a user who is already authenticated to the router into visiting a malicious website. The site can then cause unauthorized actions through portal.cgi because arbitrary csrf_token_value values are accepted.
Are users protected by the router's CSRF token mechanism?
No. The affected anti-CSRF mechanism does not validate csrf_token_value and accepts arbitrary values as valid.
Which firmware version fixes the vulnerability?
The issue is fixed in firmware version 1.1.0.651412.