CVE-2026-16771 Details
Description
In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaScript gating that can be bypassed by any HTTP client. This allows unauthenticated attackers on the LAN to read sensitive configuration data, modify persistent device settings, or trigger backend diagnostic operations. The issue appears systemic across the CGI handler chain.
An authentication bypass vulnerability has been identified in the Arris BGW210-700 gateway, specifically in firmware versions through 2.7.7. The vulnerability allows unauthenticated attackers on the local area network (LAN) to access and manipulate sensitive configuration data via the device's web management interface. This issue arises because several Common Gateway Interface (CGI) endpoints do not implement proper server-side authentication, relying instead on client-side controls that can be easily bypassed. As a result, attackers can read confidential information, alter persistent device settings, and initiate backend diagnostic processes.
The Arris BGW210-700 gateway is managed by ISPs, which typically handle firmware updates. Users should check their current firmware version and contact their ISP if they are still on an affected version. For those in environments with older firmware, standard network hygiene practices can help mitigate risks.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 28, 2026CISA-ADP
Assessed Jul 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.kb.cert.org/vuls/id/141367 | CVE | AdvisoryRemedy |
| https://kb.cert.org/vuls/id/141367 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Arris BGW210-700 | <= 2.7.7 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 28, 2026 | CVE Modified | CISA-ADP |
| Jul 28, 2026 | CVE Modified | CVE |
| Jul 28, 2026 | New CVE Received | [email protected] |
Volerion