SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-16771

HIGH · CVSS 8.8 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

The Arris BGW210-700 gateway firmware versions 2.7.7 and earlier are vulnerable due to a lack of server-side authentication on management endpoints, allowing unauthorized access via any HTTP client. This vulnerability enables attackers on the local network to read sensitive configuration data, alter device settings, or execute backend diagnostics. Network administrators and organizations using affected firmware should prioritize patching to mitigate potential exploitation.

CVE
CVE-2026-16771
Severity
HIGH
CVSS
8.8
EPSS
0.35%
Java

Original NVD Description

In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaScript gating that can be bypassed by any HTTP client. This allows unauthenticated attackers on the LAN to read sensitive configuration data, modify persistent device settings, or trigger backend diagnostic operations. The issue appears systemic across the CGI handler chain.