CVE-2026-16771
Received Received - Intake

Unauthenticated Access in Arris BGW210-700 Gateway

Vulnerability report for CVE-2026-16771, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: CERT/CC

Description

In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaScript gating that can be bypassed by any HTTP client. This allows unauthenticated attackers on the LAN to read sensitive configuration data, modify persistent device settings, or trigger backend diagnostic operations. The issue appears systemic across the CGI handler chain.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-29
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
arris bgw210-700 *
arris bgw210-700 to 2.7.7 (exc)
at&t arris_bgw210-700 to 2.7.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-16771 is an authentication bypass flaw in the Arris BGW210-700 gateway firmware versions 2.7.7 and earlier. The device fails to enforce server-side authentication on its management endpoints, relying only on client-side checks that can be bypassed. This allows unauthenticated LAN users to access sensitive data or modify settings.

Detection Guidance

Check the firmware version of your Arris BGW210-700 gateway via the router's diagnostic settings. If it is version 2.7.7 or earlier, the device is vulnerable. You can also attempt to access management endpoints like /cgi-bin/*.ha without authentication to confirm the flaw.

Impact Analysis

Unauthenticated attackers on your local network could read WiFi passwords, change network settings, or trigger diagnostic operations. This could lead to unauthorized access to your network, data exposure, or service disruptions. Devices with firmware older than 2.7.7 are at risk.

Compliance Impact

This vulnerability could lead to non-compliance with data protection regulations such as GDPR or HIPAA if sensitive configuration data or user information is exposed or modified without authorization. Unauthorized access to WiFi passwords or device settings may violate privacy requirements under these standards.

Mitigation Strategies

Update the firmware to the latest version provided by your ISP. If updates are unavailable, isolate untrusted devices from the LAN and restrict access to the gateway's management interface. Contact your ISP to ensure automated updates are applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16771. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart