CVE-2017-9490: Arris TG1682G Firmware

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The Comcast firmware on Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices allows configuration changes via CSRF.

Affected products

  • Arris TG1682G Firmware: version 10.0.132.sip.pc20.ct only; version tg1682_2.2p7s2_prod_sey only
  • Cisco DPC3939B Firmware: version dpc3939b-v303r204217-150321a-cmcst only

Published 2017-07-31. Last modified 2026-06-17.