CyberRota Analysis
AI-GeneratedThe Arris BGW210-700 gateway firmware versions 2.7.7 and earlier are vulnerable due to a lack of server-side authentication on management endpoints, allowing unauthorized access via any HTTP client. This vulnerability enables attackers on the local network to read sensitive configuration data, alter device settings, or execute backend diagnostics. Network administrators and organizations using affected firmware should prioritize patching to mitigate potential exploitation.
Original NVD Description
In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaScript gating that can be bypassed by any HTTP client. This allows unauthenticated attackers on the LAN to read sensitive configuration data, modify persistent device settings, or trigger backend diagnostic operations. The issue appears systemic across the CGI handler chain.