Junglewise Threat Intelligence

CVE-2026-16771: Arris BGW210-700 authentication bypass in management endpoints

CVE-2026-16771 · Severity: info · CVSS 8.8 · Published 2026-07-28

Executive brief

The Arris BGW210-700 is a residential gateway used to provide internet and WiFi connectivity. A security flaw in older firmware allows anyone connected to the local network to bypass the password prompt and access the device's management settings. An attacker could use this to steal the WiFi password, change network settings, or disrupt internet service.

Technical details

An authentication bypass vulnerability exists in the Arris BGW210-700 gateway due to a failure to implement server-side authorization checks on /cgi-bin/*.ha endpoints. While the web interface displays an 'Access Code' prompt, this is enforced only via client-side CSS and JavaScript, which can be bypassed by direct HTTP requests. An unauthenticated attacker on the local network (LAN) can access endpoints like wconfig_unified.ha to retrieve plaintext WiFi keys, broadbandconfig.ha to modify WAN settings, and diag.ha to run diagnostic operations. This issue affects firmware versions 2.7.7 and earlier; however, most devices receive automatic ISP-managed updates that mitigate the risk.

Affected products

  • Arris BGW210-700 gateway 2.7.7 and earlier

Timeline

  • 2026-04-17: disclosed: Vendor notified
  • 2026-07-28: advisory: CERT/CC and NVD advisory published

References