VU#141367: AT&T's Arris BGW210-700 gateway contains authentication bypass vulnerability in LAN-side management interface
The Arris BGW210-700 residential gateway, utilized by AT&T, has a critical security flaw in firmware versions 2.7.7 and earlier. This vulnerability, CVE-2026-16771, allows unauthenticated users on the local network to access sensitive configuration data and alter device settings. The web management interface bypasses server-side authentication, relying only on client-side code, which can be easily circumvented. An attacker can exploit this to retrieve the WiFi password in plaintext and modify network configurations. Multiple diagnostic and configuration pages are affected, including those for WiFi settings and WAN parameters. The impact includes unauthorized network access and manipulation. Fortunately, most devices should have received automatic firmware updates from ISPs, rendering them unaffected. Users can check their firmware version through the device's web interface. It is recommended to confirm automatic update functionality with the ISP. Practicing good network hygiene, like isolating devices and monitoring for unknown clients, can further mitigate risks.