CVE-2015-7290: Arris Na Model 862 Gw Mono Firmware

Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in adv_pwd_cgi in the web management interface on Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 allows remote attackers to inject arbitrary web script or HTML via the pwd parameter.

Affected products

  • Arris Na Model 862 Gw Mono Firmware: version ts070593c_073013 only; version ts0703128_100611 only; version ts0703135_112211 only; version ts0705125_062314 only; version ts0705125d_031115 only

Published 2015-11-21. Last modified 2026-06-17.