CVE-2026-16771
CVE-2026-16771
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaScript gating that can be bypassed by any HTTP client. This allows unauthenticated attackers on the LAN to read sensitive configuration data, modify persistent device settings, or trigger backend diagnostic operations. The issue appears systemic across the CGI handler chain.
| Vendor | at&t |
| Product | arris bgw210‑700 |
| Published | Jul 28, 2026 |
| Last Updated | Jul 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for at&t arris bgw210‑700
Be the first to know when new high vulnerabilities affecting at&t arris bgw210‑700 are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
AT&T / Arris BGW210‑700
0 ≤ 2.7.7