Beveiligingsadvies

CVE-2026-40857

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-16 11:21:14
Laatst bijgewerkt 2026-09-16 16:00:47
Toegewezen door CERT-PL
CVSS-score 8.4
Status PUBLISHED

Beschrijving

WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value parameter, accepting any arbitrary value as valid. This allows a remote attacker to perform unauthorized actions on the device by tricking an authenticated user into visiting a malicious website.This issue has been fixed in firmware version 1.1.0.651412