Medium severity6.1NVD Advisory· Published Nov 16, 2017· Updated May 13, 2026
CVE-2017-16836
CVE-2017-16836
Description
Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via the actionHandler/ajax_managed_services.php service parameter.
Affected products
1- cpe:2.3:o:commscope:arris_tg1682g_firmware:10.0.59.sip.pc20.ct:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- packetstormsecurity.com/files/134288/Arris-TG1682G-Modem-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/38657/nvdExploitThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.