← Back

Arris

arris

27 CVEs • 43 products

Products (43)

Click to collapse
Toggle
Cadant C3 Cmts
cadant_c3_cmts
Dg860a
dg860a
Tg862a
tg862a
Tg862g
tg862g
Sbr Ac1900p
sbr-ac1900p
Sbr Ac3200p
sbr-ac3200p
Sbr Ac1200p
sbr-ac1200p
Nvg443
nvg443
Nvg599
nvg599
Nvg589
nvg589
Nvg510
nvg510
Bgw210
bgw210
Bgw320
bgw320
Nvg443b
nvg443b
Tg852g
tg852g
Tg1672g
tg1672g
Dg1670a
dg1670a
Vap2500
vap2500

CVEs (27)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Arris
1Touchstone Tg862g/ct Firmware
May 6, 2026
Dec 17, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allows remote authenticated users to inject arbitrary web script or HTML via the computer_name...Show more
Cross-site scripting (XSS) vulnerability in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allows remote authenticated users to inject arbitrary web script or HTML via the computer_name parameter to connected_devices_computers_edit.php.Show less
1Arris
1Touchstone Tg862g/ct Firmware
May 6, 2026
Dec 17, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allow remote attackers to hijack the authentication of administrators for re...Show more
Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) enable remote management via a request to remote_management.php, (2) add a port forwarding rule via a request to port_forwarding_add.php, (3) change the wireless network to open via a request to wireless_network_configuration_edit.php, or (4) conduct cross-site scripting (XSS) attacks via the keyword parameter to managed_sites_add_keyword.php.Show less
1Arris
1Vap2500 Firmware
May 6, 2026
Nov 28, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files.
1Arris
1Vap2500 Firmware
May 6, 2026
Nov 28, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication.
1Arris
1Vap2500 Firmware
May 6, 2026
Nov 28, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands via unknown vectors.
1Arris
2Touchstone Dg950a
Touchstone Dg950a Software
May 6, 2026
Sep 5, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote attackers to obtain sensitive password, key, and SSID information via an SNMP request.
1Arris
1Cadant C3 Cmts
Apr 23, 2026
Jun 12, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
Arris Cadant C3 CMTS allows remote attackers to cause a denial of service (service termination) via a malformed IP packet with an invalid IP option.