{"document":{"acknowledgments":[{"urls":["https://kb.cert.org/vuls/id/141367#acknowledgements"]}],"category":"CERT/CC Vulnerability Note","csaf_version":"2.0","notes":[{"category":"summary","text":"### Overview\r\nFirmware versions 2.7.7 and earlier of the Arris BGW210-700 residential gateway contain an authentication bypass vulnerability, tracked as CVE-2026-16771, that allows any unauthenticated LAN-side user to read sensitive configuration data and modify device settings through web management endpoints. Although this vulnerability was recently discovered, the majority of in-service gateways are not expected to be running the affected version. Only devices that have not received automated ISP-managed firmware updates since version 2.7.7 in 2020 are vulnerable. \r\n\r\n### Description\r\nThe Arris BGW210-700 is a residential gateway used widely in AT&T deployments to provide routing, wireless networking, and wide-area network (WAN) connectivity for home users. The device exposes a browser-based management interface on the local-area network (LAN) side that allows users to configure WiFi settings, check diagnostics, and run system operations.\r\n\r\nSeveral CGI (Common Gateway Interface) handlers within the BGW210-700's web interface do not enforce any server-side authentication checks. Although the interface presents an \"Access Code\" prompt to users, this restriction is entirely implemented through client-side HTML and JavaScript and is not validated by the server before processing requests. As a result, any HTTP client that ignores client-side code can directly access and interact with the underlying CGI endpoints.\r\n\r\nThe lack of server-side authentication affects multiple configuration and diagnostic pages. The `wconfig_unified.ha` endpoint returns the plaintext WiFi pre-shared key for all configured SSIDs to any unauthenticated requester. The `broadbandconfig.ha` endpoint accepts unauthenticated POST requests that directly modify WAN configuration parameters, including settings that persist across device reboots. Additional diagnostic endpoints, such as `diag.ha`, allow unauthenticated triggering of backend diagnostic jobs. \r\n\r\n### Impact\r\nThis vulnerability allows any unauthenticated user on the LAN, including devices connected to the gateway through the main WiFi network, Guest WiFi network, or LAN ethernet, to read sensitive configuration information and make persistent changes to gateway settings. A local attacker can retrieve the network's plaintext WiFi password with a single HTTP request and achieve unauthorized access to manipulate, intrude on, and interfere with protected networks.\r\n\r\n### Solution\r\nThis gateway is ISP-managed, so all standard internet-connected devices are expected to have been automatically updated to newer unaffected versions. Users can determine their active version by checking their router's diagnostic settings via web browser, and optionally contact their ISP to confirm that automatic updates are functioning correctly. Because the vulnerability is limited to the LAN-side management interface, standard network hygiene practices such as isolating untrusted devices, keeping IoT systems updated, and monitoring for the presence of unknown clients can further reduce risk in environments where older firmware may still be present.\r\n\r\n### Acknowledgements\r\nThanks to David Weekly for researching and reporting this vulnerability.  This document was written by Molly Jaconski.","title":"Summary"},{"category":"legal_disclaimer","text":"THIS DOCUMENT IS PROVIDED ON AN 'AS IS' BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. ","title":"Legal Disclaimer"},{"category":"other","text":"CERT/CC Vulnerability Note is a limited advisory. It primarily identifies vendors impacted by the advisory and not specific products. We only support \"known_affected\" and \"known_not_affected\" status. Please consult the vendor's statements and advisory URL if provided by the vendor for more details ","title":"Limitations of Advisory"},{"category":"other","text":"The reported vulnerability was evaluated to determine applicability, exposure, and operational risk within the production environment. Analysis confirmed that the submitted findings were based on older firmware version 2.7.7, which is no longer deployed within our production network. Additionally, the issues described have been addressed in later firmware releases.\r\nAs a result, the vulnerability has been assessed as non applicable to AT&T current production state, and the associated CERT case will be updated and closed with a no impact designation.","title":"Vendor statment from AT&T"}],"publisher":{"category":"coordinator","contact_details":"Email: cert@cert.org, Phone: +1412 268 5800","issuing_authority":"CERT/CC under DHS/CISA https://www.cisa.gov/cybersecurity also see https://kb.cert.org/ ","name":"CERT/CC","namespace":"https://kb.cert.org/"},"references":[{"url":"https://certcc.github.io/certcc_disclosure_policy","summary":"CERT/CC vulnerability disclosure policy"},{"summary":"CERT/CC document released","category":"self","url":"https://kb.cert.org/vuls/id/141367"}],"title":"AT&T's Arris BGW210-700 gateway contains authentication bypass vulnerability in LAN-side management interface","tracking":{"current_release_date":"2026-07-28T18:43:48+00:00","generator":{"engine":{"name":"VINCE","version":"3.0.43"}},"id":"VU#141367","initial_release_date":"2026-07-28 18:19:12.146651+00:00","revision_history":[{"date":"2026-07-28T18:43:48+00:00","number":"1.20260728184348.3","summary":"Released on 2026-07-28T18:43:48+00:00"}],"status":"final","version":"1.20260728184348.3"}},"vulnerabilities":[{"title":"In firmware versions 2.","notes":[{"category":"summary","text":"In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaScript gating that can be bypassed by any HTTP client. This allows unauthenticated attackers on the LAN to read sensitive configuration data, modify persistent device settings, or trigger backend diagnostic operations. The issue appears systemic across the CGI handler chain."}],"cve":"CVE-2026-16771","ids":[{"system_name":"CERT/CC V Identifier ","text":"VU#141367"}],"product_status":{"known_not_affected":["CSAFPID-a6911914-8ad1-11f1-ad74-123eceb31d7b"]}}],"product_tree":{"branches":[{"category":"vendor","name":"AT&T","product":{"name":"AT&T Products","product_id":"CSAFPID-a6911914-8ad1-11f1-ad74-123eceb31d7b"}}]}}