TL;DR
CERT/CC disclosed an Arris BGW210-700 vulnerability tracked as CVE-2026-16771. The authentication bypass affects firmware 2.7.7 and earlier. Any unauthenticated LAN user can read settings and change the AT&T gateway’s configuration.
- CVE: CVE-2026-16771
- CVSS: 8.8 (High · CVSSv3)
- Product: AT&T Arris BGW210‑700
- Affected: ≤ 2.7.7
- Impact: CVE-2026-16771
- Status: No confirmed exploitation yet
- EPSS: 0.3% (30-day)
- Action: See vendor advisory
Why it matters
The BGW210-700 is a common residential gateway in AT&T homes. Therefore a single flaw can expose many home networks. An attacker on the WiFi or LAN needs no password to abuse it.
With one HTTP request, an attacker can grab the plaintext WiFi key. As a result, they can join the network and reach every device on it. Worse, some changes persist across reboots.
How the attack works
Client-side checks only
Several CGI handlers skip server-side authentication. The gateway shows an “Access Code” prompt, but CERT/CC notes this check “is entirely implemented through client-side HTML and JavaScript.” So any HTTP client that ignores that code reaches the endpoints directly.
Exposed endpoints
One endpoint “returns the plaintext WiFi pre-shared key for all configured SSIDs.” Another accepts unauthenticated changes to WAN settings. A diagnostic endpoint even runs backend jobs on demand. The MITRE record rates the Arris BGW210-700 vulnerability at CVSS 8.8.
Affected versions
The Arris BGW210-700 vulnerability affects firmware 2.7.7 and earlier. Most in-service units already received automatic ISP updates. CERT/CC expects few live gateways to still run the affected version. No public exploitation or proof-of-concept has been confirmed for this flaw.
Patch and mitigation
Check your firmware version in the router’s diagnostics page. This gateway is ISP-managed, so most devices update on their own. Confirm with AT&T that automatic updates work. Meanwhile, isolate untrusted devices and watch for unknown clients.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.