What is CVE-2026-16771?
The Arris BGW210‑700 gateway, in firmware versions 2.7.7 and earlier, does not enforce any server-side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client-side CSS/JavaScript gating that can be easily bypassed. This allows unauthenticated attackers on the local network to access the device's management functions. It is recommended to update to the latest firmware version.
Azərbaycanca: Arris BGW210‑700 gateway cihazının 2.7.7 və daha əvvəlki firmware versiyalarında /cgi-bin/*.ha idarəetmə endpoint-ləri server-side autentifikasiya tətbiq etmir, yalnız client-side CSS/JavaScript maneələrinə etibar edir. Bu zəiflik autentifikasiya olunmamış təcavüzkarlara LAN daxilindən cihazın idarə panelinə giriş imkanı verir. Cihazı ən son firmware versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
How is authentication implemented on the /cgi-bin/*.ha endpoints of the Arris BGW210‑700?
The device does not enforce any server-side authentication on these endpoints, relying solely on client-side CSS/JavaScript gating that can be easily bypassed.
From where does an attacker need to operate to exploit CVE-2026-16771?
This vulnerability allows unauthenticated attackers on the local network to access the device's management functions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.