CVE-2017-16836: Commscope Arris TG1682G Firmware
Medium severity, CVSS 6.1. EPSS: 2% chance of exploitation in the next 30 days.
Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via the actionHandler/ajax_managed_services.php service parameter.
Affected products
- Commscope Arris TG1682G Firmware: version 10.0.59.sip.pc20.ct only
Published 2017-11-16. Last modified 2026-06-17.