In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaScript gating that can be bypassed by any HTTP client. This allows unauthenticated attackers on the LAN to read sensitive configuration data, modify persistent device settings, or trigger backend diagnostic operations. The issue appears systemic across the CGI handler chain.
References
Configurations
No configuration.
History
28 Jul 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| CWE | CWE-306 |
28 Jul 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-28 19:17
Updated : 2026-07-30 19:10
NVD link : CVE-2026-16771
Mitre link : CVE-2026-16771
CVE.ORG link : CVE-2026-16771
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
