🔐 CVE Alert

CVE-2026-16771

HIGH 8.8

CVE-2026-16771

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaScript gating that can be bypassed by any HTTP client. This allows unauthenticated attackers on the LAN to read sensitive configuration data, modify persistent device settings, or trigger backend diagnostic operations. The issue appears systemic across the CGI handler chain.

Vendor at&t
Product arris bgw210‑700
Published Jul 28, 2026
Last Updated Jul 28, 2026
Stay Ahead of the Next One

Get instant alerts for at&t arris bgw210‑700

Be the first to know when new high vulnerabilities affecting at&t arris bgw210‑700 are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

AT&T / Arris BGW210‑700
0 ≤ 2.7.7

References

NVD ↗ CVE.org ↗ EPSS Data ↗
kb.cert.org: https://kb.cert.org/vuls/id/141367 kb.cert.org: https://www.kb.cert.org/vuls/id/141367