VYPR

BGW210

by Arris

CVEs (2)

  • CVE-2022-31793HigAug 4, 2022
    risk 0.50cvss 7.5epss 0.16

    do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before a desired path on the filesystem. This occurs because the code skips over the first character when serving files. Arris NVG443,…

  • CVE-2026-16771HigJul 28, 2026
    risk 0.00cvss 8.8epss 0.00

    In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaScript gating that can be bypassed by any HTTP client. This allows…