Back to overview

CVE-2026-16771

HIGH
8.8
CVSS 3.1
Description
In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaScript gating that can be bypassed by any HTTP client. This allows unauthenticated attackers on the LAN to read sensitive configuration data, modify persistent device settings, or trigger backend diagnostic operations. The issue appears systemic across the CGI handler chain.

Metadata

CVE ID
CVE-2026-16771
State
PUBLISHED
Assigner
certcc
Reserved
2026-07-23 16:36 UTC
Published
2026-07-28 18:21 UTC
Last updated
2026-07-28 19:31 UTC
Primary CWE
CWE-306
CWE-306 Missing Authentication for Critical Function
Vendor / Product
AT&T / Arris BGW210‑700
Sources
cve.org  ·  NVD

Severity & Metrics

8.8 HIGH CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
AT&T Arris BGW210‑700 0 ≤ 2.7.7
Weakness (CWE)
CWESourceDescription
cna CWE-306 Missing Authentication for Critical Function
CWE-306 adp CWE-306 Missing Authentication for Critical Function
CVSS scores (1)
ScoreSeverityVersionSourceVector
8.8 HIGH 3.1 adp CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview