THE Arris BGW210-700 has a critical vulnerability tracked as CVE-2026-16771, disclosed by CERT/CC. This authentication bypass affects firmware versions 2.7.7 and earlier, allowing unauthenticated LAN users to access sensitive settings and modify the AT&T gateway's configuration. The CVSS score is 8.8, indicating high severity.
Key points include the risk of attackers obtaining the plaintext WiFi key to join networks, the methodology of client-side checks bypassing server-side authentication, and the fact that most in-use devices likely received automatic updates, reducing the number of vulnerable units. Users are advised to check firmware versions and consult AT&T for confirmation on automatic updates, while isolating untrusted devices.