arris CVE Vulnerabilities & Metrics

Focus on arris vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About arris Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with arris. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total arris CVEs: 16
Earliest CVE date: 12 Jun 2007, 18:30 UTC
Latest CVE date: 27 Dec 2023, 20:15 UTC

Latest CVE reference: CVE-2023-40038

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical arris CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.9

Max CVSS: 10.0

Critical CVEs (≥9): 4

CVSS Range vs. Count

Range Count
0.0-3.9 5
4.0-6.9 7
7.0-8.9 8
9.0-10.0 4

CVSS Distribution Chart

Top 5 Highest CVSS arris CVEs

These are the five CVEs with the highest CVSS scores for arris, sorted by severity first and recency.

All CVEs for arris

CVE-2023-40038 arris vulnerability CVSS: 0 27 Dec 2023, 20:15 UTC

Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. (They use the first 6 characters of the SSID and the last 6 characters of the BSSID, decrementing the last digit.)

CVE-2023-40039 arris vulnerability CVSS: 0 11 Sep 2023, 07:15 UTC

An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame.

CVE-2022-45028 arris vulnerability CVSS: 0 13 Dec 2022, 18:15 UTC

A cross-site scripting (XSS) vulnerability in Arris NVG443B 9.3.0h3d36 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request sent to /cgi-bin/logs.ha.

CVE-2022-31793 arris vulnerability CVSS: 0 04 Aug 2022, 22:15 UTC

do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before a desired path on the filesystem. This occurs because the code skips over the first character when serving files. Arris NVG443, NVG599, NVG589, and NVG510 devices and Arris-derived BGW210 and BGW320 devices are affected.

CVE-2022-26994 arris vulnerability CVSS: 7.5 15 Mar 2022, 22:15 UTC

Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the pptp function via the pptpUserName and pptpPassword parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVE-2022-26993 arris vulnerability CVSS: 7.5 15 Mar 2022, 22:15 UTC

Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the pppoe function via the pppoeUserName, pppoePassword, and pppoe_Service parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVE-2022-26992 arris vulnerability CVSS: 7.5 15 Mar 2022, 22:15 UTC

Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the ddns function via the DdnsUserName, DdnsHostName, and DdnsPassword parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVE-2022-26991 arris vulnerability CVSS: 7.5 15 Mar 2022, 22:15 UTC

Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the ntp function via the TimeZone parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVE-2022-26990 arris vulnerability CVSS: 7.5 15 Mar 2022, 22:15 UTC

Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the firewall-local log function via the EmailAddress, SmtpServerName, SmtpUsername, and SmtpPassword parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVE-2020-8438 arris vulnerability CVSS: 9.0 29 Jan 2020, 23:15 UTC

Ruckus ZoneFlex R500 104.0.0.0.1347 devices allow an authenticated attacker to execute arbitrary OS commands via the hidden /forms/nslookupHandler form, as demonstrated by the nslookuptarget=|cat${IFS} substring.

CVE-2018-20383 arris vulnerability CVSS: 5.0 23 Dec 2018, 21:29 UTC

ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

CVE-2017-9490 arris vulnerability CVSS: 6.8 31 Jul 2017, 03:29 UTC

The Comcast firmware on Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices allows configuration changes via CSRF.

CVE-2015-7291 arris vulnerability CVSS: 6.8 21 Nov 2015, 11:59 UTC

Cross-site request forgery (CSRF) vulnerability in adv_pwd_cgi in the web management interface on Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 allows remote attackers to hijack the authentication of arbitrary users.

CVE-2015-7290 arris vulnerability CVSS: 4.3 21 Nov 2015, 11:59 UTC

Cross-site scripting (XSS) vulnerability in adv_pwd_cgi in the web management interface on Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 allows remote attackers to inject arbitrary web script or HTML via the pwd parameter.

CVE-2015-7289 arris vulnerability CVSS: 9.3 21 Nov 2015, 11:59 UTC

Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 have a hardcoded administrator password derived from a serial number, which makes it easier for remote attackers to obtain access via the web management interface, SSH, TELNET, or SNMP.

CVE-2009-5149 arris vulnerability CVSS: 4.3 21 Nov 2015, 11:59 UTC

Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 have predictable technician passwords, which makes it easier for remote attackers to obtain access via the web management interface, related to a "password of the day" issue.

CVE-2014-9406 arris vulnerability CVSS: 10.0 18 Dec 2014, 15:59 UTC

ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier has a default password of password for the admin account, which makes it easier for remote attackers to obtain access via a request to home_loggedout.php.

CVE-2014-5438 arris vulnerability CVSS: 3.5 17 Dec 2014, 18:59 UTC

Cross-site scripting (XSS) vulnerability in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allows remote authenticated users to inject arbitrary web script or HTML via the computer_name parameter to connected_devices_computers_edit.php.

CVE-2014-5437 arris vulnerability CVSS: 6.8 17 Dec 2014, 18:59 UTC

Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) enable remote management via a request to remote_management.php, (2) add a port forwarding rule via a request to port_forwarding_add.php, (3) change the wireless network to open via a request to wireless_network_configuration_edit.php, or (4) conduct cross-site scripting (XSS) attacks via the keyword parameter to managed_sites_add_keyword.php.

CVE-2014-8425 arris vulnerability CVSS: 7.8 28 Nov 2014, 15:59 UTC

The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files.

CVE-2014-8424 arris vulnerability CVSS: 7.8 28 Nov 2014, 15:59 UTC

ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication.

CVE-2014-8423 arris vulnerability CVSS: 10.0 28 Nov 2014, 15:59 UTC

Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands via unknown vectors.

CVE-2014-4863 arris vulnerability CVSS: 5.0 05 Sep 2014, 17:55 UTC

The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote attackers to obtain sensitive password, key, and SSID information via an SNMP request.

CVE-2007-2796 arris vulnerability CVSS: 7.8 12 Jun 2007, 18:30 UTC

Arris Cadant C3 CMTS allows remote attackers to cause a denial of service (service termination) via a malformed IP packet with an invalid IP option.