Authentication Bypass Vulnerability in Arris BGW210-700 Gateway
CVE-2026-16771

8.8HIGH

Key Information:

Vendor

At&t

Vendor
CVE Published:
28 July 2026

What is CVE-2026-16771?

The Arris BGW210-700 gateway contains an authentication bypass vulnerability due to insufficient server-side authentication on its management endpoints. In firmware versions 2.7.7 and earlier, attackers within the local area network (LAN) can easily bypass client-side checks reliant on CSS and JavaScript. This vulnerability enables unauthorized users to access sensitive configuration data, change device settings, or initiate internal diagnostic operations, effectively compromising the device's integrity and security.

Affected Version(s)

Arris BGW210‑700 0 <= 2.7.7

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.