In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaScript gating that can be bypassed by any HTTP client. This allows unauthenticated attackers on the LAN to read sensitive configuration data, modify persistent device settings, or trigger backend diagnostic operations. The issue appears systemic across the CGI handler chain.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://kb.cert.org/vuls/id/141367 |
|
History
Tue, 28 Jul 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
At&t
At&t arris Bgw210‑700 |
|
| Vendors & Products |
At&t
At&t arris Bgw210‑700 |
Tue, 28 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-306 | |
| Metrics |
cvssV3_1
|
Tue, 28 Jul 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaScript gating that can be bypassed by any HTTP client. This allows unauthenticated attackers on the LAN to read sensitive configuration data, modify persistent device settings, or trigger backend diagnostic operations. The issue appears systemic across the CGI handler chain. | |
| Title | CVE-2026-16771 | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-07-28T19:31:06.344Z
Reserved: 2026-07-23T16:36:49.550Z
Link: CVE-2026-16771
Updated: 2026-07-28T19:31:06.344Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-28T20:38:33Z