CVE-2026-16771

AT&T / Arris · BGW210-700

The AT&T Arris BGW210-700 firmware contains a missing authentication vulnerability in critical functions, allowing unauthorized access from the local network.

Executive summary

A critical authentication bypass flaw in the AT&T Arris BGW210-700 gateway exposes sensitive device functions to unauthorized access from the local network.

Vulnerability

This vulnerability (CWE-306) involves missing authentication for critical functions within the device firmware. An attacker on the local network can access these functions without providing valid credentials.

Business impact

The ability to access critical device functions without authentication can lead to full device compromise, including the ability to change network settings, intercept traffic, or disable security features. With a CVSS score of 8.8, this poses a severe risk to the security of the local network environment.

Remediation

Immediate Action: Check the manufacturer support portal for available firmware updates beyond version 2.7.7, and apply them as soon as they are made available.

Proactive Monitoring: Monitor device logs for unauthorized configuration changes and verify that only authorized devices are connected to the local network.

Compensating Controls: If a patch is unavailable, restrict physical and logical access to the management interface to trusted administrative devices only.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Due to the critical nature of the device, users should contact their ISP for guidance on firmware updates. Mitigating this risk is essential to prevent unauthorized control of the network gateway.