CVE-2017-16836: Commscope Arris TG1682G Firmware

Medium severity, CVSS 6.1. EPSS: 2% chance of exploitation in the next 30 days.

Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via the actionHandler/ajax_managed_services.php service parameter.

Affected products

  • Commscope Arris TG1682G Firmware: version 10.0.59.sip.pc20.ct only

Published 2017-11-16. Last modified 2026-06-17.