US ISP Network Security Scorecard
Original research from AIMF Security Services analyzing CVE vulnerability history and built-in security features across the five major US internet service providers. We scored each ISP's gateway equipment on network segmentation, device tracking, bridge mode, firewall capabilities, and CVE track record to answer one question: whose router should you trust?
Executive Summary
Most Americans don't choose their router — their ISP does. When you sign up for internet service, the gateway modem/router combo they mail you becomes the first and most critical layer of security for every device in your home. Yet few consumers know whether that box has been patched, whether it can isolate IoT devices, or whether it's had known vulnerabilities exploited in the wild.
This research paper evaluates the gateway equipment deployed by nine major US internet providers — Comcast Xfinity, Frontier, Verizon Fios, T-Mobile 5G, Cox, AT&T, CenturyLink, Spectrum, and Optimum — across two equally weighted dimensions: CVE vulnerability history (50%) and built-in security features (50%). We reviewed 20+ CVEs from the NVD database and documented each provider's gateway models, firmware update practices, and consumer-facing security capabilities.
Key Findings:
- #1 — Comcast Xfinity: 81.5/100 (B+) thanks to a clean recent CVE record on current-generation gateways and the most robust consumer security suite (xFi CyberSecure).
- #2 — Frontier Fiber: 77.5/100 (B) — only one CVE (DoS) on eero, bridge mode natively, and ONT architecture means no ISP gateway lock-in.
- #3 (tie) — Verizon Fios: 76.5/100 (B) with enterprise SPI firewall and bridge mode, but legacy G1100 CVEs.
- #3 (tie) — T-Mobile 5G: 76.5/100 (B) with zero CVEs and bridge mode on KVD21, but limited features.
- #5 — Cox: 74.0/100 (B) with Panoramic WiFi Advanced Security and bridge mode, but legacy TG1682 CVEs.
- #6 (tie) — AT&T: 64.0/100 (C) with ActiveArmor, but CVE-2022-31793 and no true bridge mode.
- #6 (tie) — CenturyLink: 64.0/100 (C) with Secure WiFi, but Zyxel CVE history including a CISA KEV listing.
- #8 — Spectrum: 60.0/100 (C-) with Security Shield, but limited bridge mode and Sagemcom CVE history.
- #9 — Optimum/Altice: 55.0/100 (D+) due to Sagemcom CVE history and the worst bridge mode support in the industry.
Critical Gap Across Most ISPs: Of the nine ISPs studied, only Frontier's eero Business tier offers true network segmentation (up to 4 separate networks). Every other provider puts your smart TV, laptop, baby monitor, and security cameras on the same flat network. This is the single biggest security weakness in ISP-provided hardware and the strongest argument for using bridge mode with your own router.
The Rankings
Final scores out of 100, combining CVE history (50 points) and security features (50 points).
Comcast Xfinity
xFi CyberSecure + full bridge mode + clean recent CVE record
Frontier Fiber
eero mesh + only 1 CVE (DoS) + ONT means no gateway lock-in + eero Business offers 4 separate networks
Verizon Fios
Enterprise SPI firewall + bridge mode, but legacy G1100 CVEs
T-Mobile 5G Home Internet
Zero CVEs on record + bridge mode on KVD21, but limited features
Cox Communications
Panoramic WiFi app + Advanced Security + bridge mode, legacy TG1682 CVEs
AT&T
ActiveArmor + Smart Home Manager, but CVE-2022-31793 + no true bridge mode
CenturyLink/Lumen
Secure WiFi + Premium WiFi app, but Zyxel vendor CVEs (CVSS 9.8) + CISA KEV listing
Spectrum
Security Shield + WiFi 7, but limited bridge mode + Sagemcom CVE history
Optimum/Altice
Advanced Security ($5/mo), but Sagemcom CVE-2021-3304 (CVSS 9.8) + worst bridge mode support
Scoring Methodology
Each ISP received a score out of 100 points, split equally between two categories: CVE vulnerability history (50 points) and built-in security features (50 points). Data was collected from the NIST National Vulnerability Database (NVD), FCC equipment filings, manufacturer documentation, ISP support pages, and independent security research publications.
CVE Vulnerability History
- CVE Count (20 pts): Number of CVEs affecting current and recent gateway models within the 2021–2026 data window. Fewer CVEs = higher score.
- Max Severity (15 pts): Highest CVSS score among documented CVEs. Lower max severity = higher score.
- Patch Responsiveness (10 pts): Whether the ISP pushed automatic firmware updates to remediate known vulnerabilities.
- CISA KEV Listing (5 pts): Whether any CVEs appeared on the CISA Known Exploited Vulnerabilities catalog.
Built-in Security Features
- Network Segmentation (12.5 pts): Ability to isolate IoT devices, create separate VLANs, or maintain distinct network zones for different device classes.
- Device Tracking & Alerts (12.5 pts): Visibility into connected devices, new device notifications, and ability to block/pause unknown devices.
- Bridge Mode (12.5 pts): Ability to disable the gateway's routing function and use your own router/firewall. True bridge mode scores higher than IP passthrough.
- Firewall & Extras (12.5 pts): SPI firewall, WPA3 support, automatic firmware updates, parental controls, intrusion detection, and content filtering.
Data Limitations: ISP gateway deployment is not publicly documented at the model level. We analyzed the gateway models most commonly deployed by each ISP based on FCC filings, support documentation, and community reports. Actual equipment may vary by region and installation date. CVE data reflects NVD records as of August 2026 and may not include vulnerabilities discovered but not yet assigned a CVE ID.
Full Scorecard
Detailed breakdown of each ISP's score across all dimensions.
| ISP | CVE Count (/20) | Max Severity (/15) | Patch Speed (/10) | CISA KEV (/5) | Segmentation (/12.5) | Device Track (/12.5) | Bridge Mode (/12.5) | Firewall+ (/12.5) | Total (/100) |
|---|---|---|---|---|---|---|---|---|---|
| Comcast Xfinity | 18 | 12 | 8 | 5 | 4 | 11 | 12.5 | 11 | 81.5 |
| Frontier Fiber | 18 | 13 | 5 | 5 | 6 | 10 | 12.5 | 8 | 77.5 |
| Verizon Fios | 15 | 11 | 8 | 5 | 5 | 8 | 12.5 | 12 | 76.5 |
| T-Mobile 5G | 20 | 15 | 9 | 5 | 2 | 6 | 12.5 | 7 | 76.5 |
| Cox | 16 | 11 | 8 | 5 | 4 | 10 | 10 | 10 | 74.0 |
| AT&T | 14 | 10 | 7 | 5 | 4 | 10 | 5 | 9 | 64.0 |
| CenturyLink | 14 | 8 | 7 | 2 | 4 | 10 | 10 | 9 | 64.0 |
| Spectrum | 12 | 10 | 7 | 5 | 4 | 10 | 3 | 9 | 60.0 |
| Optimum | 12 | 7 | 6 | 5 | 4 | 10 | 3 | 8 | 55.0 |
Score Comparison Chart
CVE History (blue) vs. Security Features (green) — 50 points each.
CVE History Score (out of 50)
Security Features Score (out of 50)
Feature Comparison Matrix
Side-by-side comparison of key security capabilities across all nine ISPs.
| Feature | Xfinity | Frontier | Verizon | T-Mobile | Cox | AT&T | CenturyLink | Spectrum | Optimum |
|---|---|---|---|---|---|---|---|---|---|
| True Bridge Mode | Yes | Yes (eero + ONT) | Yes | Yes (KVD21) | Yes | No (IP Passthrough) | Yes (transparent) | Limited | No (locked interface) |
| Network Segmentation | No | Yes (eero Business: 4 networks) | No | No | No | No | No | No | No |
| Guest WiFi Network | Yes | Yes | Yes | Limited | Yes | Yes | Yes | Yes | Yes |
| Device List Visibility | Yes (xFi app) | Yes (eero app) | Yes (My Fios) | Basic (T-Life app) | Yes (Cox WiFi app) | Yes (Smart Home) | Yes (My CenturyLink) | Yes (My Spectrum) | Yes (My Optimum) |
| New Device Alerts | Yes (CyberSecure) | Yes (eero app) | Limited | No | Yes (Advanced Security) | Yes (ActiveArmor) | Yes (Secure WiFi) | Yes (Security Shield) | Yes (Advanced Security) |
| Pause / Block Devices | Yes | Yes | Limited | Basic | Yes | Yes | Yes (groups) | Yes | Yes |
| SPI Firewall | Yes | No (eero has no SPI) | Yes (Enterprise-grade) | No (carrier-managed) | Yes | Basic | Yes (stealth mode) | Yes | Basic |
| WPA3 Support | Yes (XB7+) | Yes (all eero 6+) | Yes (G3100+) | Yes | Yes (CGM4331+) | Yes (BGW320+) | Yes (C4000+) | Yes (WiFi 6E+) | Yes (UBC1326) |
| Automatic Firmware Updates | Yes | Yes (eero auto) | Yes | Yes (OTA) | Yes | Yes | Yes | Yes | Yes |
| Intrusion Detection | Yes (CyberSecure) | Threat blocking (eero Secure) | Yes (DoS protection) | Bitdefender (Nokia only) | Yes (Advanced Security) | Yes (ActiveArmor) | Yes (Secure WiFi) | Yes (Security Shield) | Yes (Advanced Security) |
| Parental Controls | Yes | Yes | Yes | Basic pause only | Yes (profiles) | Yes | Yes (schedules) | Yes | Yes (profiles) |
| Content Filtering | Yes | Yes (eero Secure) | Yes (URL/keyword) | No | Yes | Yes | Yes (category blocking) | Limited | Yes (web filtering) |
| DMZ Host Support | Yes | No (eero) | Yes | No | Yes | Limited | Yes | Limited | No |
| Malware / Phishing Blocking | Yes (CyberSecure) | Yes (eero Secure) | Home Network Protection | Bitdefender (Nokia) | Yes (Advanced Security) | Yes (ActiveArmor) | Yes (Secure WiFi) | Yes (Security Shield) | Yes (Advanced Security) |
| Security Suite Cost | Included | Paid ($10/mo Wi-Fi Security+) | Included | Included | Included | Included | Included | Included | Paid ($5/mo) |
ISP-by-ISP Analysis
Detailed breakdown of each provider's gateway equipment, CVE history, and security feature set.
Comcast Xfinity
Gateway Models
🛡️ Security Features
🚨 CVE History (2021–2026)
| CVE ID | CVSS | Model | Year |
|---|---|---|---|
| No CVEs on current-generation gateways (XB7/XB8/XB10) in the 2021–2026 window | |||
Legacy models (TG1682G, DPC3941T, DPC3939) had 7+ CVEs from 2016–2018 including CSRF, XSS, default credentials, and SSID disclosure. These models are being phased out. Current XB7/XB8/XB10 gateways have a clean record.
Why Xfinity ranks first: The clean CVE record on current-generation hardware, combined with the most robust consumer security suite (xFi CyberSecure with real-time threat monitoring and new-device alerts), and full bridge mode for users who want to use their own router. The main weakness is the lack of network segmentation — a gap shared by all but one ISP in this study.
Frontier Fiber
Gateway Models
🛡️ Security Features
🚨 CVE History
| CVE ID | CVSS | Model | Description |
|---|---|---|---|
| CVE-2023-5324 | 6.5 MEDIUM | eeroOS (all eero models) | Ethernet interface DoS — crafted IPv6 packet with zero-length options header causes ~8 min Ethernet outage. WiFi unaffected. Requires adjacent network access. |
Only one CVE across the entire eero product line. The vulnerability is a denial-of-service (not remote code execution) and requires adjacent network access. However, eero's patch response was notably slow — the issue was reported in August 2022 and was still present in September 2023 testing (eeroOS v6.15.2-99), taking over 14 months to remediate. Not listed on CISA KEV.
Why Frontier ranks second: Frontier's eero mesh system is the only ISP equipment in this study that offers true network segmentation — eero Business supports up to 4 separate networks (staff, guest, devices, etc.). The ONT-to-Ethernet architecture means there's no ISP gateway lock-in at all; you can connect any router with a WAN port directly to the ONT. Only one CVE (a DoS, not RCE) across the entire eero line. The main deductions are for the slow patch response on CVE-2023-5324 and the lack of an SPI firewall on consumer eero models.
Verizon Fios
Gateway Models
🛡️ Security Features
🚨 CVE History
| CVE ID | CVSS | Model | Description |
|---|---|---|---|
| CVE-2019-3914 | 7.2 HIGH | G1100 | Authenticated remote command injection via crafted hostname in access control rule |
| CVE-2019-3915 | 8.1 HIGH | G1100 | Login replay attack — unauthenticated attacker can capture and replay admin login |
| CVE-2019-3916 | 7.5 HIGH | G1100 | Password salt disclosure via unauthenticated API URL access |
All three CVEs affect the legacy G1100 (Fios Quantum Gateway) only. Verizon patched all three with firmware 02.02.00.13. No CVEs have been filed against the current-generation G3100 or CR1000A/CR1000B. The CR1000A received a "B" security grade from independent assessment site ismyroutersafe.com.
Why Verizon ranks second: The enterprise-grade SPI firewall with intrusion detection and DoS protection is the best firewall implementation among consumer ISPs. Bridge mode is fully supported. The main deductions are for the G1100 CVE history (though patched and on legacy hardware) and less granular device tracking compared to Xfinity's CyberSecure.
T-Mobile 5G Home Internet
Gateway Models
🛡️ Security Features
🚨 CVE History (2021–2026)
| CVE ID | CVSS | Model | Year |
|---|---|---|---|
| Zero CVEs on record for KVD21, 5G21, or G4AR as of August 2026 | |||
T-Mobile's gateways have a clean CVE record. The firmware uses signed, encrypted bootloader firmware with no public method to unlock or reflash. Regular OTA updates include security and stability improvements. However, the locked-down nature of these devices also means security researchers have limited ability to audit them, so the absence of CVEs may partly reflect limited public scrutiny rather than superior security.
Why T-Mobile ties for third: A perfect CVE score (zero vulnerabilities) and bridge mode on the KVD21 push T-Mobile into the top tier. However, the extremely limited feature set — no customizable firewall, no content filtering, no advanced device management — prevents it from ranking higher. T-Mobile's gateways are secure by virtue of being locked down, not by virtue of offering robust security tools. The Nokia 5G21's Bitdefender integration is a plus, but it's not available on the Arcadyan models.
Cox Communications
Gateway Models
🛡️ Security Features
🚨 CVE History
| CVE ID | CVSS | Model | Description |
|---|---|---|---|
| CVE-2017-9490 | 6.5 MED | TG1682G | CSRF — configuration changes via cross-site request forgery |
| CVE-2017-16836 | 6.1 MED | TG1682G | Unauthenticated stored XSS via actionHandler/ajax_managed_services.php |
| CVE-2018-10989 | 6.6 MED | TG1682G | Default password "password" on admin account over unencrypted HTTP |
| CVE-2018-10990 | 5.4 MED | TG1682G | Insufficient session expiration — credential cookie persists after logout |
| CVE-2017-9476 | 6.5 MED | TG1682G | Hidden SSID and passphrase disclosure for Home Security WiFi network |
All 5 CVEs affect the legacy Arris TG1682G, which Cox shares with Comcast. Current-generation CGM4141 and CGM4331 gateways have no CVEs in the 2021–2026 window. Not listed on CISA KEV.
Why Cox ranks fifth: Cox's Panoramic WiFi platform is functionally similar to Comcast's xFi, with Advanced Security providing 24/7 threat monitoring and real-time alerts. Bridge mode is well-documented and supported. The legacy TG1682G CVEs are a concern for customers still using older equipment, but the current CGM4331 (WiFi 6) has a clean record. Cox loses points relative to Xfinity for slightly less granular device management and no equivalent to xFi CyberSecure's adaptive threat learning.
AT&T
Gateway Models
🛡️ Security Features
🚨 CVE History
| CVE ID | CVSS | Model | Description |
|---|---|---|---|
| CVE-2022-31793 | 7.5 HIGH | NVG443, NVG599, NVG589, NVG510, BGW210, BGW320 | muhttpd path traversal — unauthenticated remote file read as root. Can recover WiFi password, admin password, SIP credentials, and ISP TR-069 endpoint credentials. |
Discovered by security researcher Derek Abdine in 2022, this vulnerability in the muhttpd web server affects virtually all Arris-derived AT&T gateways. At least 19,000 Internet-facing vulnerable routers were identified at the time of disclosure. The vulnerability existed in muhttpd since 2006. AT&T patched affected gateways via automatic firmware update. Not listed on CISA KEV.
Why AT&T ranks sixth: The CVE-2022-31793 path traversal is one of the most severe CVEs in this study — it allowed unauthenticated remote attackers to read arbitrary files as root, including WiFi passwords and admin credentials, on both legacy and current-gen gateways. While patched, the 16-year-old vulnerability is concerning. Combined with the lack of true bridge mode (AT&T's IP Passthrough is a workaround, not a real bridge), this places AT&T in the bottom tier. The Smart Home Manager app and ActiveArmor are good consumer tools, but they can't compensate for the gateway's architectural limitations.
CenturyLink / Lumen
Gateway Models
🛡️ Security Features
🚨 CVE History
| CVE ID | CVSS | Product Line | Description |
|---|---|---|---|
| CVE-2020-29583 | 9.8 CRIT | Zyxel USG/ZLD | Undocumented hardcoded account (zyfwp) with cleartext password in firmware — SSH/web admin access. Same vendor as C3000Z. |
| CVE-2024-40891 | 8.6 HIGH | Zyxel DSL CPE | Post-auth command injection via Telnet on legacy Zyxel DSL CPE. CISA KEV listed. |
| CVE-2020-29299 | 8.8 HIGH | Zyxel USG/VPN | Command injection via password change input string. Same vendor as C3000Z. |
No CVEs have been filed specifically against the C3000Z or C4000 models. However, Zyxel (manufacturer of the C3000Z) has had serious security issues across its product lines, including a CVSS 9.8 hardcoded credential vulnerability and a CISA KEV-listed command injection. The C4000 series is manufactured by Greenwave/Actiontec, which has a cleaner CVE record. The Zyxel vendor risk is the primary reason CenturyLink scores low on CVE history.
Why CenturyLink ties for sixth: While the C3000Z and C4000 don't have direct CVEs, the Zyxel brand has a troubling security track record including a CVSS 9.8 hardcoded credential vulnerability and a CISA KEV listing for command injection on DSL CPE. The firewall with stealth mode is a plus, and transparent bridge mode is available. The My CenturyLink app with device groups and content controls is competitive. But the Zyxel vendor risk and CISA KEV listing drag the score down significantly.
Spectrum
Gateway Models
🛡️ Security Features
🚨 CVE History
| CVE ID | CVSS | Model | Description |
|---|---|---|---|
| CVE-2020-24034 | 8.8 HIGH | Sagemcom F@st 5280 (RAC2V1S) | Insecure deserialization allowing privilege escalation to internal account — attacker can flash custom firmware for complete compromise |
The Sagemcom F@st 5280 (distributed as Spectrum RAC2V1S) had a critical privilege escalation vulnerability allowing authenticated users to achieve complete device compromise by flashing custom firmware. Additionally, multiple Hitron CVEs (CVE-2024-28089 XSS, CVE-2025-44179 command injection, CVE-2023-30602 cleartext credentials) affect Hitron equipment, though these target Hitron-branded models not confirmed as Spectrum deployments. Not listed on CISA KEV.
Why Spectrum ranks eighth: The CVSS 8.8 privilege escalation on the Sagemcom F@st 5280 (allowing complete device compromise), combined with limited bridge mode support and restricted advanced settings. Spectrum's Security Shield is a capable AI-enabled protection tool, and the new WiFi 7 router is modern hardware, but the overall security posture is weakened by the CVE history and the lack of user control over the gateway's routing function.
Optimum / Altice
Gateway Models
🛡️ Security Features
🚨 CVE History
| CVE ID | CVSS | Product | Description |
|---|---|---|---|
| CVE-2021-3304 | 9.8 CRIT | Sagemcom F@st 3686 | Buffer overflow via long sessionKey to goform/login URI — unauthenticated remote code execution. Same vendor as Optimum gateways. |
| CVE-2024-1623 | 7.5 HIGH | Sagemcom F@st 3686 | Insufficient session timeout — local attacker can access admin panel without login credentials. |
| CVE-2019-19494 | 8.0 HIGH | Sagemcom F@st 3686/3890 | Broadcom cable modem buffer overflow — remote kernel-level code execution via JavaScript in victim's browser. |
| CVE-2026-31195 | 8.8 HIGH | Altice Labs GR140DG | OS command injection in ping diagnostic — authenticated remote attackers can execute commands as root. Altice Labs is Optimum's parent company. |
No CVEs have been filed specifically against the UBC1326. However, Sagemcom (the manufacturer) has multiple critical CVEs on similar gateway products, including a CVSS 9.8 unauthenticated buffer overflow. Additionally, Altice Labs (Optimum's parent company) had a 2026 command injection CVE on its fiber router. The combination of Sagemcom vendor risk and Altice Labs CVEs creates significant concern. Not listed on CISA KEV for Optimum-specific equipment.
Why Optimum ranks last: Optimum has the worst bridge mode support in the industry — the gateway's web interface is locked down by the ISP via DOCSIS configuration files, and users report being unable to disable NAT or access advanced settings. The Sagemcom vendor has a CVSS 9.8 unauthenticated RCE on similar products. Advanced Security is a paid add-on ($5/mo), unlike most competitors who include security features at no extra cost. The DNS-based protection explicitly does not protect against inbound network attacks. For users who want to use their own router, Optimum is the most restrictive ISP in this study.
Key Findings & Analysis
1. Only One ISP Offers True Network Segmentation
This is the most significant finding of the study. Despite the well-documented risks of IoT devices sharing a flat network with computers and phones, only Frontier's eero Business tier offers true network segmentation (up to 4 separate networks). The other eight ISPs put your smart TV, laptop, baby monitor, and security cameras on the same flat network. Guest WiFi networks exist on most platforms, but these are designed for visitor access, not for isolating 47 smart home devices from your work laptop.
This means that a compromised smart bulb, baby monitor, or smart TV can potentially reach every other device on your network. For security-conscious users, this is the strongest argument for using bridge mode (where available) and deploying your own router with VLAN capabilities.
2. Bridge Mode Is Not Universal
Of the nine ISPs studied, six offer true bridge mode: Comcast Xfinity, Frontier (eero + ONT), Verizon Fios, T-Mobile (KVD21), Cox, and CenturyLink (transparent bridge). AT&T does not offer bridge mode at all — their IP Passthrough feature is a workaround. Spectrum's bridge mode support is poorly documented and appears limited. Optimum has the worst bridge mode support in the industry — the gateway's web interface is locked down by the ISP, and users cannot disable NAT or access advanced settings.
Bridge mode is critical because it lets you bypass the ISP gateway's routing and security limitations by using your own router. Without it, you're stuck with whatever security features your ISP decides to provide. Frontier's ONT architecture is the gold standard — fiber terminates at an ONT and Ethernet runs to any router you choose, with no ISP gateway in the path at all.
3. CVE History Favors Newer Platforms
T-Mobile's 5G gateways have zero CVEs, Frontier's eero line has only one (a DoS), and Comcast's current-generation XB7/XB8/XB10 gateways also have a clean record. However, this may partly reflect the age of the equipment and the level of public scrutiny rather than superior security engineering. The Arris/Technicolor gateways used by Comcast, Cox, and AT&T have been extensively studied by security researchers (notably the Bastille Research CableTap disclosures), while T-Mobile's locked-down Arcadyan/Nokia devices have received less public auditing.
4. ISP-Managed Security Suites Are Getting Better
Comcast's xFi CyberSecure, AT&T's ActiveArmor, Cox's Advanced Security, CenturyLink's Secure WiFi, and Spectrum's Security Shield all represent meaningful improvements in consumer network security. These cloud-managed services provide malware blocking, phishing protection, and device behavior monitoring that would have required a dedicated security appliance just a few years ago. However, they all operate at the network level and cannot replace device-level security (antivirus, OS patches, etc.). Notably, Optimum charges $5/mo for its Advanced Security add-on, while every other ISP in this study includes security features at no extra cost.
5. The Sagemcom/Arris Vendor Risk Is Significant
Three of the bottom four ISPs (Optimum, Spectrum, and CenturyLink) use equipment from vendors with serious CVE histories. Sagemcom has a CVSS 9.8 unauthenticated buffer overflow (CVE-2021-3304) on its F@st 3686 line, plus session timeout and Broadcom cable modem buffer overflow CVEs. Zyxel has a CVSS 9.8 hardcoded credential vulnerability (CVE-2020-29583) and a CISA KEV-listed command injection (CVE-2024-40891). Arris has the muhttpd path traversal (CVE-2022-31793) affecting AT&T gateways. When your ISP chooses your equipment, you inherit their vendor's security track record.
6. The muhttpd Vulnerability Remains the Most Concerning Finding
CVE-2022-31793, affecting AT&T's Arris-derived gateways, is particularly alarming because the underlying muhttpd web server vulnerability had existed since 2006 — 16 years before it was publicly disclosed. This means millions of AT&T gateways were vulnerable to unauthenticated root-level file reads for over a decade. While patched after disclosure, this illustrates the risk of ISP-managed firmware: vulnerabilities can persist for years without independent auditing.
Recommendations
If you're a Comcast Xfinity customer
You have the best default security posture of any ISP in this study. Keep xFi CyberSecure enabled, use the Xfinity app to review connected devices regularly, and set your firewall to Medium or High. If you have advanced security needs (IoT isolation, custom VLANs, VPN routing), enable bridge mode and use your own router.
If you're a Frontier Fiber customer
Your eero mesh system is the most flexible ISP equipment in this study. If you have eero Business, configure up to 4 separate networks to isolate IoT devices, guest devices, and work equipment. If you need even more control, connect your own router directly to the ONT — no ISP gateway required. Consider subscribing to Wi-Fi Security Plus for VPN, ad blocking, and enhanced threat protection. Keep eero auto-updates enabled to ensure CVE-2023-5324 and future vulnerabilities are patched.
If you're a Verizon Fios customer
Your gateway has the best firewall in the study. Ensure your G3100 or CR1000A is running the latest firmware. Enable Home Network Protection and configure content filtering if you have children. If you're still using a G1100, request an upgrade — the legacy CVEs have been patched, but the hardware is aging. Bridge mode is available if you need VLAN isolation.
If you're a T-Mobile 5G customer
Your gateway has a clean CVE record, but the limited feature set means you should strongly consider enabling bridge mode (available on the KVD21 via the T-Life app) and using your own router. This gives you VLAN segmentation, a customizable firewall, and advanced device management that T-Mobile's locked-down gateway doesn't offer. If you have the Nokia 5G21, Bitdefender cybersecurity is included.
If you're a Cox Communications customer
Keep Panoramic WiFi Advanced Security enabled and use the Cox WiFi app for device management. If you have a legacy TG1682 gateway, request an upgrade to the CGM4331 (WiFi 6) — the legacy CVEs are a risk. Bridge mode is available if you need VLAN isolation or want to use your own router. Cox also supports customer-owned modems, which gives you full control over your network equipment.
If you're an AT&T customer
Ensure your BGW320 or BGW210 has been updated to patch CVE-2022-31793 (automatic updates should handle this). Enable ActiveArmor via the Smart Home Manager app. Since AT&T doesn't offer true bridge mode, use IP Passthrough to forward your public IP to your own router — it's not perfect, but it's the best option available. Disable the BGW's WiFi radios if you're using your own access points.
If you're a CenturyLink/Lumen customer
If you have a C3000Z (Zyxel), consider upgrading to the C4000 series (Greenwave) to reduce Zyxel vendor risk. Enable Secure WiFi and use the My CenturyLink app for device groups and content controls. The C3000Z supports transparent bridge mode — use it with your own router for VLAN segmentation and a customizable firewall. Be aware that Zyxel has had CISA KEV-listed vulnerabilities on its DSL CPE product line.
If you're a Spectrum customer
If you have a Sagemcom F@st 5280 (RAC2V1S), request an upgrade to the WiFi 6E or WiFi 7 router — the CVE-2020-24034 privilege escalation is a serious risk. Keep Security Shield enabled and use the My Spectrum app for device management. Spectrum's limited bridge mode support means you may need to purchase your own modem and router to get full control over your network security.
If you're an Optimum/Altice customer
You have the most restrictive ISP in this study. The gateway's web interface is locked, NAT cannot be disabled, and bridge mode is effectively unavailable. If you need network segmentation or a customizable firewall, your only option is to purchase your own DOCSIS 3.1 modem (Optimum allows customer-owned modems) and use your own router. If you subscribe to Advanced Security ($5/mo), be aware that it's DNS-based and explicitly does not protect against inbound network attacks.
Universal Recommendation: Regardless of your ISP, the single most impactful security upgrade you can make is to use bridge mode (or IP Passthrough) with your own router that supports VLAN network segmentation. This isolates your IoT devices from your computers and phones, gives you a real firewall you can configure, and removes your dependence on ISP-managed firmware updates. See our Network Defense Hub for router recommendations and setup guides.
Is Your Network Secure?
Get a professional network security assessment from AIMF Security Services. We'll audit your home or business network, identify vulnerabilities in your router and connected devices, and provide a prioritized remediation plan.
Sources & References
- NIST National Vulnerability Database (NVD) — CVE-2022-31793, CVE-2020-24034, CVE-2020-29583, CVE-2024-40891, CVE-2020-29299, CVE-2023-5324, CVE-2021-3304, CVE-2024-1623, CVE-2019-19494, CVE-2026-31195, CVE-2019-3914/3915/3916, CVE-2017-9490/9476/9487/16836, CVE-2018-10989/10990/15907, CVE-2016-7454, CVE-2024-28089, CVE-2025-44179, CVE-2025-63354, CVE-2023-30602 — nvd.nist.gov
- Derek Abdine, "Arris Router Critical Vulnerability Advisory" (2022) — derekabdine.com
- Tenable Research, "Verizon Fios Quantum Gateway Routers Patched for Multiple Vulnerabilities" (2019) — tenable.com
- Bastille Research, CableTap Vulnerability Disclosures — github.com/BastilleResearch
- Comcast Xfinity, "xFi CyberSecure" support documentation — xfinity.com
- AT&T, "Smart Home Manager" and "ActiveArmor" support documentation — att.com
- Verizon, Fios Router G3100/CR1000A User Guides — verizon.com
- Spectrum, "Advanced WiFi" and WiFi 7 Router User Guide — spectrum.com
- T-Mobile, "Arcadyan KVD21 Gateway" and "Nokia 5G21 Gateway" support pages — t-mobile.com
- Cox Communications, "Panoramic WiFi" and "Advanced Security" support documentation — cox.com
- CenturyLink, "Secure WiFi" and "C4000/C3000Z Modem User Guides" — centurylink.com
- Frontier, "Wi-Fi Security" and "eero Setup Guide" — frontier.com
- eero, "Advanced Features" support documentation — eero.com
- Optimum, "Advanced Security" product page and subscriber portal guide — optimum.com
- CISA Known Exploited Vulnerabilities Catalog — CVE-2024-40891 (Zyxel DSL CPE) — cisa.gov
- FCC Equipment Authorization filings (XB10: P27XB10, KVD21, G4AR: RAXTMOG4AR, CGM4141: G95CGM414X) — fccid.io
- ismyroutersafe.com, Verizon CR1000A Security Assessment — ismyroutersafe.com
- DSLReports, Spectrum Branded Equipment Guide — dslreports.com
- nomis, "eeroOS Ethernet Interface DoS Vulnerability (CVE-2023-5324)" — github.com/nomis
- Zyxel Security Advisory, "Command Injection and Insecure Default Credentials in Legacy DSL CPE" (2025) — zyxel.com
Research conducted by AIMF Security Services, September 2026. This research paper is provided for informational purposes only and does not constitute professional security advice. ISP gateway deployments vary by region and may change over time. Verify your specific equipment model and firmware version with your ISP.