US ISP Network Security Scorecard

Which Internet Provider's Gateway Is Actually Secure? (2021–2026)

Original research from AIMF Security Services analyzing CVE vulnerability history and built-in security features across the five major US internet service providers. We scored each ISP's gateway equipment on network segmentation, device tracking, bridge mode, firewall capabilities, and CVE track record to answer one question: whose router should you trust?

Published: September 2026 Data Window: 2021–2026 9 ISPs Analyzed 20+ CVEs Reviewed 4 Feature Dimensions

Executive Summary

Most Americans don't choose their router — their ISP does. When you sign up for internet service, the gateway modem/router combo they mail you becomes the first and most critical layer of security for every device in your home. Yet few consumers know whether that box has been patched, whether it can isolate IoT devices, or whether it's had known vulnerabilities exploited in the wild.

This research paper evaluates the gateway equipment deployed by nine major US internet providers — Comcast Xfinity, Frontier, Verizon Fios, T-Mobile 5G, Cox, AT&T, CenturyLink, Spectrum, and Optimum — across two equally weighted dimensions: CVE vulnerability history (50%) and built-in security features (50%). We reviewed 20+ CVEs from the NVD database and documented each provider's gateway models, firmware update practices, and consumer-facing security capabilities.

Key Findings:

  • #1 — Comcast Xfinity: 81.5/100 (B+) thanks to a clean recent CVE record on current-generation gateways and the most robust consumer security suite (xFi CyberSecure).
  • #2 — Frontier Fiber: 77.5/100 (B) — only one CVE (DoS) on eero, bridge mode natively, and ONT architecture means no ISP gateway lock-in.
  • #3 (tie) — Verizon Fios: 76.5/100 (B) with enterprise SPI firewall and bridge mode, but legacy G1100 CVEs.
  • #3 (tie) — T-Mobile 5G: 76.5/100 (B) with zero CVEs and bridge mode on KVD21, but limited features.
  • #5 — Cox: 74.0/100 (B) with Panoramic WiFi Advanced Security and bridge mode, but legacy TG1682 CVEs.
  • #6 (tie) — AT&T: 64.0/100 (C) with ActiveArmor, but CVE-2022-31793 and no true bridge mode.
  • #6 (tie) — CenturyLink: 64.0/100 (C) with Secure WiFi, but Zyxel CVE history including a CISA KEV listing.
  • #8 — Spectrum: 60.0/100 (C-) with Security Shield, but limited bridge mode and Sagemcom CVE history.
  • #9 — Optimum/Altice: 55.0/100 (D+) due to Sagemcom CVE history and the worst bridge mode support in the industry.

Critical Gap Across Most ISPs: Of the nine ISPs studied, only Frontier's eero Business tier offers true network segmentation (up to 4 separate networks). Every other provider puts your smart TV, laptop, baby monitor, and security cameras on the same flat network. This is the single biggest security weakness in ISP-provided hardware and the strongest argument for using bridge mode with your own router.

The Rankings

Final scores out of 100, combining CVE history (50 points) and security features (50 points).

1

Comcast Xfinity

xFi CyberSecure + full bridge mode + clean recent CVE record

81.5
B+
2

Frontier Fiber

eero mesh + only 1 CVE (DoS) + ONT means no gateway lock-in + eero Business offers 4 separate networks

77.5
B
3

Verizon Fios

Enterprise SPI firewall + bridge mode, but legacy G1100 CVEs

76.5
B
3

T-Mobile 5G Home Internet

Zero CVEs on record + bridge mode on KVD21, but limited features

76.5
B
5

Cox Communications

Panoramic WiFi app + Advanced Security + bridge mode, legacy TG1682 CVEs

74.0
B
6

AT&T

ActiveArmor + Smart Home Manager, but CVE-2022-31793 + no true bridge mode

64.0
C
6

CenturyLink/Lumen

Secure WiFi + Premium WiFi app, but Zyxel vendor CVEs (CVSS 9.8) + CISA KEV listing

64.0
C
8

Spectrum

Security Shield + WiFi 7, but limited bridge mode + Sagemcom CVE history

60.0
C-
9

Optimum/Altice

Advanced Security ($5/mo), but Sagemcom CVE-2021-3304 (CVSS 9.8) + worst bridge mode support

55.0
D+

Scoring Methodology

Each ISP received a score out of 100 points, split equally between two categories: CVE vulnerability history (50 points) and built-in security features (50 points). Data was collected from the NIST National Vulnerability Database (NVD), FCC equipment filings, manufacturer documentation, ISP support pages, and independent security research publications.

50 Points — 50%

CVE Vulnerability History

  • CVE Count (20 pts): Number of CVEs affecting current and recent gateway models within the 2021–2026 data window. Fewer CVEs = higher score.
  • Max Severity (15 pts): Highest CVSS score among documented CVEs. Lower max severity = higher score.
  • Patch Responsiveness (10 pts): Whether the ISP pushed automatic firmware updates to remediate known vulnerabilities.
  • CISA KEV Listing (5 pts): Whether any CVEs appeared on the CISA Known Exploited Vulnerabilities catalog.
50 Points — 50%

Built-in Security Features

  • Network Segmentation (12.5 pts): Ability to isolate IoT devices, create separate VLANs, or maintain distinct network zones for different device classes.
  • Device Tracking & Alerts (12.5 pts): Visibility into connected devices, new device notifications, and ability to block/pause unknown devices.
  • Bridge Mode (12.5 pts): Ability to disable the gateway's routing function and use your own router/firewall. True bridge mode scores higher than IP passthrough.
  • Firewall & Extras (12.5 pts): SPI firewall, WPA3 support, automatic firmware updates, parental controls, intrusion detection, and content filtering.

Data Limitations: ISP gateway deployment is not publicly documented at the model level. We analyzed the gateway models most commonly deployed by each ISP based on FCC filings, support documentation, and community reports. Actual equipment may vary by region and installation date. CVE data reflects NVD records as of August 2026 and may not include vulnerabilities discovered but not yet assigned a CVE ID.

Full Scorecard

Detailed breakdown of each ISP's score across all dimensions.

Click the table to view full size
ISPCVE Count
(/20)
Max Severity
(/15)
Patch Speed
(/10)
CISA KEV
(/5)
Segmentation
(/12.5)
Device Track
(/12.5)
Bridge Mode
(/12.5)
Firewall+
(/12.5)
Total
(/100)
Comcast Xfinity18128541112.51181.5
Frontier Fiber18135561012.5877.5
Verizon Fios1511855812.51276.5
T-Mobile 5G2015952612.5776.5
Cox161185410101074.0
AT&T1410754105964.0
CenturyLink1487241010964.0
Spectrum1210754103960.0
Optimum127654103855.0

Score Comparison Chart

CVE History (blue) vs. Security Features (green) — 50 points each.

CVE History Score (out of 50)

T-Mobile 5G
49
Frontier Fiber
41
Comcast Xfinity
43
Cox
40
Verizon Fios
39
AT&T
36
CenturyLink
31
Spectrum
34
Optimum
30

Security Features Score (out of 50)

Comcast Xfinity
38.5
Verizon Fios
37.5
Frontier Fiber
36.5
Cox
34.0
CenturyLink
33.0
AT&T
28.0
T-Mobile 5G
27.5
Spectrum
26.0
Optimum
25.0

Feature Comparison Matrix

Side-by-side comparison of key security capabilities across all nine ISPs.

Yes No Limited / Paid
FeatureXfinityFrontierVerizonT-MobileCoxAT&TCenturyLinkSpectrumOptimum
True Bridge ModeYesYes (eero + ONT)YesYes (KVD21)YesNo (IP Passthrough)Yes (transparent)LimitedNo (locked interface)
Network SegmentationNoYes (eero Business: 4 networks)NoNoNoNoNoNoNo
Guest WiFi NetworkYesYesYesLimitedYesYesYesYesYes
Device List VisibilityYes (xFi app)Yes (eero app)Yes (My Fios)Basic (T-Life app)Yes (Cox WiFi app)Yes (Smart Home)Yes (My CenturyLink)Yes (My Spectrum)Yes (My Optimum)
New Device AlertsYes (CyberSecure)Yes (eero app)LimitedNoYes (Advanced Security)Yes (ActiveArmor)Yes (Secure WiFi)Yes (Security Shield)Yes (Advanced Security)
Pause / Block DevicesYesYesLimitedBasicYesYesYes (groups)YesYes
SPI FirewallYesNo (eero has no SPI)Yes (Enterprise-grade)No (carrier-managed)YesBasicYes (stealth mode)YesBasic
WPA3 SupportYes (XB7+)Yes (all eero 6+)Yes (G3100+)YesYes (CGM4331+)Yes (BGW320+)Yes (C4000+)Yes (WiFi 6E+)Yes (UBC1326)
Automatic Firmware UpdatesYesYes (eero auto)YesYes (OTA)YesYesYesYesYes
Intrusion DetectionYes (CyberSecure)Threat blocking (eero Secure)Yes (DoS protection)Bitdefender (Nokia only)Yes (Advanced Security)Yes (ActiveArmor)Yes (Secure WiFi)Yes (Security Shield)Yes (Advanced Security)
Parental ControlsYesYesYesBasic pause onlyYes (profiles)YesYes (schedules)YesYes (profiles)
Content FilteringYesYes (eero Secure)Yes (URL/keyword)NoYesYesYes (category blocking)LimitedYes (web filtering)
DMZ Host SupportYesNo (eero)YesNoYesLimitedYesLimitedNo
Malware / Phishing BlockingYes (CyberSecure)Yes (eero Secure)Home Network ProtectionBitdefender (Nokia)Yes (Advanced Security)Yes (ActiveArmor)Yes (Secure WiFi)Yes (Security Shield)Yes (Advanced Security)
Security Suite CostIncludedPaid ($10/mo Wi-Fi Security+)IncludedIncludedIncludedIncludedIncludedIncludedPaid ($5/mo)

ISP-by-ISP Analysis

Detailed breakdown of each provider's gateway equipment, CVE history, and security feature set.

Comcast Xfinity

Rank #1 — Score: 81.5/100
B+ 81.5/100

Gateway Models

XB10
Sercomm — DOCSIS 4.0, WiFi 7
Current (2025+)
XB8 (CGM44980COM)
CommScope/Arris — DOCSIS 3.1, WiFi 6E
Current
XB7 (TG4482)
Arris — DOCSIS 3.1, WiFi 6
Current
TG1682G
Arris — DOCSIS 3.0, WiFi AC
Legacy
DPC3941T
Technicolor — DOCSIS 3.0
Legacy
DPC3939
Cisco — DOCSIS 3.0
Legacy

🛡️ Security Features

xFi CyberSecure (malware/phishing blocking, real-time device monitoring)
Full bridge mode (disables routing, use your own router)
Device tracking with new-device alerts via Xfinity app
Firewall: Low / Medium / High / Custom security levels
WPA2/WPA3, parental controls, guest WiFi
Automatic firmware updates (ISP-managed)
No VLAN/IoT network segmentation
~ Guest WiFi only (not true isolation)

🚨 CVE History (2021–2026)

CVE IDCVSSModelYear
No CVEs on current-generation gateways (XB7/XB8/XB10) in the 2021–2026 window

Legacy models (TG1682G, DPC3941T, DPC3939) had 7+ CVEs from 2016–2018 including CSRF, XSS, default credentials, and SSID disclosure. These models are being phased out. Current XB7/XB8/XB10 gateways have a clean record.

Why Xfinity ranks first: The clean CVE record on current-generation hardware, combined with the most robust consumer security suite (xFi CyberSecure with real-time threat monitoring and new-device alerts), and full bridge mode for users who want to use their own router. The main weakness is the lack of network segmentation — a gap shared by all but one ISP in this study.

Frontier Fiber

Rank #2 — Score: 77.5/100
B 77.5/100

Gateway Models

eero Max 7
Amazon eero — WiFi 7, Tri-band mesh
Current (5G/7G plans)
eero Pro 7
Amazon eero — WiFi 7, Tri-band mesh
Current (500M/1G/2G plans)
eero Pro 6 / 6+
Amazon eero — WiFi 6, Dual-band mesh
Current
eero 6
Amazon eero — WiFi 6, Dual-band mesh
Current
Calix GigaHome
Calix — WiFi 5/6 (legacy fiber)
Legacy

🛡️ Security Features

eero app (device tracking, profiles, pause, guest WiFi)
WPA3 on all eero 6+ models
Bridge mode (eero supports native bridge mode)
ONT architecture — no ISP gateway lock-in (use ANY router)
eero Business: up to 4 separate networks (true segmentation!)
Automatic firmware updates (eero auto-updates)
VLAN tagging support
~ Wi-Fi Security / eero Secure (paid add-on: $10/mo for Plus)
No SPI firewall on consumer eero
No DMZ support

🚨 CVE History

CVE IDCVSSModelDescription
CVE-2023-53246.5 MEDIUMeeroOS (all eero models)Ethernet interface DoS — crafted IPv6 packet with zero-length options header causes ~8 min Ethernet outage. WiFi unaffected. Requires adjacent network access.

Only one CVE across the entire eero product line. The vulnerability is a denial-of-service (not remote code execution) and requires adjacent network access. However, eero's patch response was notably slow — the issue was reported in August 2022 and was still present in September 2023 testing (eeroOS v6.15.2-99), taking over 14 months to remediate. Not listed on CISA KEV.

Why Frontier ranks second: Frontier's eero mesh system is the only ISP equipment in this study that offers true network segmentation — eero Business supports up to 4 separate networks (staff, guest, devices, etc.). The ONT-to-Ethernet architecture means there's no ISP gateway lock-in at all; you can connect any router with a WAN port directly to the ONT. Only one CVE (a DoS, not RCE) across the entire eero line. The main deductions are for the slow patch response on CVE-2023-5324 and the lack of an SPI firewall on consumer eero models.

Verizon Fios

Rank #3 (tie) — Score: 76.5/100
B 76.5/100

Gateway Models

CR1000A / CR1000B
Verizon — WiFi 6E, Tri-band
Current
G3100
Verizon — WiFi 6, Tri-band
Current
E3200
Verizon — WiFi 6 Extender
Current
G1100 (Fios Quantum)
Verizon — WiFi 5, AC1750
Legacy

🛡️ Security Features

Enterprise-grade SPI firewall (Stateful Packet Inspection)
Intrusion detection with DoS protection (ping of death, IP spoofing, scanning attacks)
Full bridge mode available
WPA2/WPA3, MAC address filtering
URL/keyword content filtering, parental controls
DMZ host support, event logging, Home Network Protection
Automatic firmware updates
No VLAN/IoT network segmentation
~ Device tracking via My Fios app (less granular than Xfinity)

🚨 CVE History

CVE IDCVSSModelDescription
CVE-2019-39147.2 HIGHG1100Authenticated remote command injection via crafted hostname in access control rule
CVE-2019-39158.1 HIGHG1100Login replay attack — unauthenticated attacker can capture and replay admin login
CVE-2019-39167.5 HIGHG1100Password salt disclosure via unauthenticated API URL access

All three CVEs affect the legacy G1100 (Fios Quantum Gateway) only. Verizon patched all three with firmware 02.02.00.13. No CVEs have been filed against the current-generation G3100 or CR1000A/CR1000B. The CR1000A received a "B" security grade from independent assessment site ismyroutersafe.com.

Why Verizon ranks second: The enterprise-grade SPI firewall with intrusion detection and DoS protection is the best firewall implementation among consumer ISPs. Bridge mode is fully supported. The main deductions are for the G1100 CVE history (though patched and on legacy hardware) and less granular device tracking compared to Xfinity's CyberSecure.

T-Mobile 5G Home Internet

Rank #3 (tie) — Score: 76.5/100
B 76.5/100

Gateway Models

G4AR (Gen 4)
Arcadyan — WiFi 6, 5G SA
Current (2024+)
KVD21
Arcadyan — WiFi 6, 5G NSA
Current
5G21 (Nokia)
Nokia — WiFi 6, 5G NSA
Current

🛡️ Security Features

WPA2/WPA3 Wi-Fi security
Bridge mode on KVD21 (via T-Life app)
Automatic OTA firmware updates with security patches
Bitdefender cybersecurity (Nokia 5G21 only)
Secure boot (Wi-Fi SoC)
No customizable firewall (carrier-managed)
No network segmentation / VLANs
No content filtering, no DMZ, no port forwarding GUI
~ Basic device management via T-Life app (no web GUI)
~ Basic pause functionality, no parental controls suite

🚨 CVE History (2021–2026)

CVE IDCVSSModelYear
Zero CVEs on record for KVD21, 5G21, or G4AR as of August 2026

T-Mobile's gateways have a clean CVE record. The firmware uses signed, encrypted bootloader firmware with no public method to unlock or reflash. Regular OTA updates include security and stability improvements. However, the locked-down nature of these devices also means security researchers have limited ability to audit them, so the absence of CVEs may partly reflect limited public scrutiny rather than superior security.

Why T-Mobile ties for third: A perfect CVE score (zero vulnerabilities) and bridge mode on the KVD21 push T-Mobile into the top tier. However, the extremely limited feature set — no customizable firewall, no content filtering, no advanced device management — prevents it from ranking higher. T-Mobile's gateways are secure by virtue of being locked down, not by virtue of offering robust security tools. The Nokia 5G21's Bitdefender integration is a plus, but it's not available on the Arcadyan models.

Cox Communications

Rank #5 — Score: 74.0/100
B 74.0/100

Gateway Models

CGM4331
Technicolor — DOCSIS 3.1, WiFi 6
Current
CGM4141
Technicolor — DOCSIS 3.1, WiFi 5
Current
TG1682 (TG1682G/CX)
Arris — DOCSIS 3.0, WiFi AC
Legacy
TG2472
Arris — DOCSIS 3.0, WiFi AC
Legacy

🛡️ Security Features

Panoramic WiFi app (device tracking, profiles, pause, naming)
Advanced Security (24/7 threat monitoring, URL blocking, real-time alerts)
Bridge mode available (use your own router)
WPA3 on CGM4331 (WiFi 6), WPA2 on CGM4141
Parental controls (profiles, bedtimes, pause, content blocking)
Guest WiFi, automatic firmware updates
Panoramic WiFi Pods (mesh extenders)
No VLAN/IoT network segmentation

🚨 CVE History

CVE IDCVSSModelDescription
CVE-2017-94906.5 MEDTG1682GCSRF — configuration changes via cross-site request forgery
CVE-2017-168366.1 MEDTG1682GUnauthenticated stored XSS via actionHandler/ajax_managed_services.php
CVE-2018-109896.6 MEDTG1682GDefault password "password" on admin account over unencrypted HTTP
CVE-2018-109905.4 MEDTG1682GInsufficient session expiration — credential cookie persists after logout
CVE-2017-94766.5 MEDTG1682GHidden SSID and passphrase disclosure for Home Security WiFi network

All 5 CVEs affect the legacy Arris TG1682G, which Cox shares with Comcast. Current-generation CGM4141 and CGM4331 gateways have no CVEs in the 2021–2026 window. Not listed on CISA KEV.

Why Cox ranks fifth: Cox's Panoramic WiFi platform is functionally similar to Comcast's xFi, with Advanced Security providing 24/7 threat monitoring and real-time alerts. Bridge mode is well-documented and supported. The legacy TG1682G CVEs are a concern for customers still using older equipment, but the current CGM4331 (WiFi 6) has a clean record. Cox loses points relative to Xfinity for slightly less granular device management and no equivalent to xFi CyberSecure's adaptive threat learning.

AT&T

Rank #6 (tie) — Score: 64.0/100
C 64.0/100

Gateway Models

BGW320
Arris — WiFi 6, Fiber
Current
BGW210
Arris — WiFi 5, Fiber/VDSL
Current
BGW620 / All-Fi Hub
AT&T — WiFi 6E
Current
NVG599 / NVG589
Arris — WiFi 5, VDSL
Legacy
Pace 5268AC
Pace — WiFi 5, VDSL/IPDSL
Legacy

🛡️ Security Features

AT&T ActiveArmor internet security (malware/phishing blocking)
Smart Home Manager app (device tracking, profiles, pause, block)
WPA2/WPA3, parental controls, guest WiFi
Automatic firmware updates (ISP-managed)
~ IP Passthrough (pseudo bridge mode — NOT true bridge mode)
~ Basic firewall (not SPI-grade)
No true bridge mode (gateway must stay active for fiber authentication)
No network segmentation / VLANs

🚨 CVE History

CVE IDCVSSModelDescription
CVE-2022-317937.5 HIGHNVG443, NVG599, NVG589, NVG510, BGW210, BGW320muhttpd path traversal — unauthenticated remote file read as root. Can recover WiFi password, admin password, SIP credentials, and ISP TR-069 endpoint credentials.

Discovered by security researcher Derek Abdine in 2022, this vulnerability in the muhttpd web server affects virtually all Arris-derived AT&T gateways. At least 19,000 Internet-facing vulnerable routers were identified at the time of disclosure. The vulnerability existed in muhttpd since 2006. AT&T patched affected gateways via automatic firmware update. Not listed on CISA KEV.

Why AT&T ranks sixth: The CVE-2022-31793 path traversal is one of the most severe CVEs in this study — it allowed unauthenticated remote attackers to read arbitrary files as root, including WiFi passwords and admin credentials, on both legacy and current-gen gateways. While patched, the 16-year-old vulnerability is concerning. Combined with the lack of true bridge mode (AT&T's IP Passthrough is a workaround, not a real bridge), this places AT&T in the bottom tier. The Smart Home Manager app and ActiveArmor are good consumer tools, but they can't compensate for the gateway's architectural limitations.

CenturyLink / Lumen

Rank #6 (tie) — Score: 64.0/100
C 64.0/100

Gateway Models

C4000L / C4000X
Greenwave (Actiontec) — WiFi 6, DSL/Fiber
Current
C3000Z
Zyxel — WiFi 5, DSL/Fiber
Current
C3000A
Actiontec — WiFi 5, DSL/Fiber
Legacy (phasing out)
PK5001A
Actiontec — WiFi 4, DSL
Legacy

🛡️ Security Features

Secure WiFi (built into leased modems, auto-on)
My CenturyLink app (device tracking, groups, content controls)
Firewall with stealth mode (Low/Medium/High/Custom levels)
Transparent bridge mode available on C3000Z
WPA3 on C4000 series, WPA2 on C3000Z
Parental controls (schedules, website/service blocking, content categories)
Premium WiFi: device groups with per-group content controls
Automatic firmware updates
No VLAN/IoT network segmentation

🚨 CVE History

CVE IDCVSSProduct LineDescription
CVE-2020-295839.8 CRITZyxel USG/ZLDUndocumented hardcoded account (zyfwp) with cleartext password in firmware — SSH/web admin access. Same vendor as C3000Z.
CVE-2024-408918.6 HIGHZyxel DSL CPEPost-auth command injection via Telnet on legacy Zyxel DSL CPE. CISA KEV listed.
CVE-2020-292998.8 HIGHZyxel USG/VPNCommand injection via password change input string. Same vendor as C3000Z.

No CVEs have been filed specifically against the C3000Z or C4000 models. However, Zyxel (manufacturer of the C3000Z) has had serious security issues across its product lines, including a CVSS 9.8 hardcoded credential vulnerability and a CISA KEV-listed command injection. The C4000 series is manufactured by Greenwave/Actiontec, which has a cleaner CVE record. The Zyxel vendor risk is the primary reason CenturyLink scores low on CVE history.

Why CenturyLink ties for sixth: While the C3000Z and C4000 don't have direct CVEs, the Zyxel brand has a troubling security track record including a CVSS 9.8 hardcoded credential vulnerability and a CISA KEV listing for command injection on DSL CPE. The firewall with stealth mode is a plus, and transparent bridge mode is available. The My CenturyLink app with device groups and content controls is competitive. But the Zyxel vendor risk and CISA KEV listing drag the score down significantly.

Spectrum

Rank #8 — Score: 60.0/100
C- 60.0/100

Gateway Models

WiFi 7 Router
Spectrum-branded — WiFi 7, Tri-band
Current (2024+)
WiFi 6E Router
Spectrum-branded — WiFi 6E
Current
RAC2V1S (Wave 2)
Sagemcom — WiFi AC Wave 2
Legacy
RAC2V1K (Wave 2)
Askey — WiFi AC Wave 2
Legacy
RAC2V1A (Wave 2)
Arris — WiFi AC Wave 2
Legacy
F@st 5280
Sagemcom — WiFi AC
Legacy

🛡️ Security Features

Security Shield (AI-enabled threat protection)
My Spectrum App (device management, pause/resume, groups)
WPA3 Personal (WiFi 6E+ models), WPA2 (Wave 2)
SPI firewall (Wave 2 and newer)
Parental controls, guest WiFi, automatic firmware updates
~ Bridge mode — not clearly documented, limited support
No network segmentation / VLANs
Limited advanced settings (port forwarding via app only)

🚨 CVE History

CVE IDCVSSModelDescription
CVE-2020-240348.8 HIGHSagemcom F@st 5280 (RAC2V1S)Insecure deserialization allowing privilege escalation to internal account — attacker can flash custom firmware for complete compromise

The Sagemcom F@st 5280 (distributed as Spectrum RAC2V1S) had a critical privilege escalation vulnerability allowing authenticated users to achieve complete device compromise by flashing custom firmware. Additionally, multiple Hitron CVEs (CVE-2024-28089 XSS, CVE-2025-44179 command injection, CVE-2023-30602 cleartext credentials) affect Hitron equipment, though these target Hitron-branded models not confirmed as Spectrum deployments. Not listed on CISA KEV.

Why Spectrum ranks eighth: The CVSS 8.8 privilege escalation on the Sagemcom F@st 5280 (allowing complete device compromise), combined with limited bridge mode support and restricted advanced settings. Spectrum's Security Shield is a capable AI-enabled protection tool, and the new WiFi 7 router is modern hardware, but the overall security posture is weakened by the CVE history and the lack of user control over the gateway's routing function.

Optimum / Altice

Rank #9 — Score: 55.0/100
D+ 55.0/100

Gateway Models

UBC1326
Altice/Sagemcom — DOCSIS 3.1, WiFi 6
Current
Smart Router (Sagemcom)
Sagemcom — DOCSIS 3.0/3.1, WiFi 5/6
Current
TM3402
Arris — DOCSIS 3.1, voice only (no WiFi)
Current (voice)
Altice One
Arris/Cisco — DOCSIS 3.0
Legacy

🛡️ Security Features

Advanced Security ($5/mo add-on: DNS-based threat blocking)
My Optimum app (device tracking, profiles, pause)
WPA3 on UBC1326 (WiFi 6)
Parental controls (profiles, content filters, schedules)
Guest WiFi, automatic firmware updates
~ Web filtering (customer-configured, DNS-based)
No true bridge mode — web interface locked, NAT cannot be disabled
No SPI firewall (Advanced Security is DNS-based, not a firewall)
No network segmentation / VLANs
No DMZ support
Advanced Security is a paid add-on ($5/mo), not included

🚨 CVE History

CVE IDCVSSProductDescription
CVE-2021-33049.8 CRITSagemcom F@st 3686Buffer overflow via long sessionKey to goform/login URI — unauthenticated remote code execution. Same vendor as Optimum gateways.
CVE-2024-16237.5 HIGHSagemcom F@st 3686Insufficient session timeout — local attacker can access admin panel without login credentials.
CVE-2019-194948.0 HIGHSagemcom F@st 3686/3890Broadcom cable modem buffer overflow — remote kernel-level code execution via JavaScript in victim's browser.
CVE-2026-311958.8 HIGHAltice Labs GR140DGOS command injection in ping diagnostic — authenticated remote attackers can execute commands as root. Altice Labs is Optimum's parent company.

No CVEs have been filed specifically against the UBC1326. However, Sagemcom (the manufacturer) has multiple critical CVEs on similar gateway products, including a CVSS 9.8 unauthenticated buffer overflow. Additionally, Altice Labs (Optimum's parent company) had a 2026 command injection CVE on its fiber router. The combination of Sagemcom vendor risk and Altice Labs CVEs creates significant concern. Not listed on CISA KEV for Optimum-specific equipment.

Why Optimum ranks last: Optimum has the worst bridge mode support in the industry — the gateway's web interface is locked down by the ISP via DOCSIS configuration files, and users report being unable to disable NAT or access advanced settings. The Sagemcom vendor has a CVSS 9.8 unauthenticated RCE on similar products. Advanced Security is a paid add-on ($5/mo), unlike most competitors who include security features at no extra cost. The DNS-based protection explicitly does not protect against inbound network attacks. For users who want to use their own router, Optimum is the most restrictive ISP in this study.

Key Findings & Analysis

1. Only One ISP Offers True Network Segmentation

This is the most significant finding of the study. Despite the well-documented risks of IoT devices sharing a flat network with computers and phones, only Frontier's eero Business tier offers true network segmentation (up to 4 separate networks). The other eight ISPs put your smart TV, laptop, baby monitor, and security cameras on the same flat network. Guest WiFi networks exist on most platforms, but these are designed for visitor access, not for isolating 47 smart home devices from your work laptop.

This means that a compromised smart bulb, baby monitor, or smart TV can potentially reach every other device on your network. For security-conscious users, this is the strongest argument for using bridge mode (where available) and deploying your own router with VLAN capabilities.

2. Bridge Mode Is Not Universal

Of the nine ISPs studied, six offer true bridge mode: Comcast Xfinity, Frontier (eero + ONT), Verizon Fios, T-Mobile (KVD21), Cox, and CenturyLink (transparent bridge). AT&T does not offer bridge mode at all — their IP Passthrough feature is a workaround. Spectrum's bridge mode support is poorly documented and appears limited. Optimum has the worst bridge mode support in the industry — the gateway's web interface is locked down by the ISP, and users cannot disable NAT or access advanced settings.

Bridge mode is critical because it lets you bypass the ISP gateway's routing and security limitations by using your own router. Without it, you're stuck with whatever security features your ISP decides to provide. Frontier's ONT architecture is the gold standard — fiber terminates at an ONT and Ethernet runs to any router you choose, with no ISP gateway in the path at all.

3. CVE History Favors Newer Platforms

T-Mobile's 5G gateways have zero CVEs, Frontier's eero line has only one (a DoS), and Comcast's current-generation XB7/XB8/XB10 gateways also have a clean record. However, this may partly reflect the age of the equipment and the level of public scrutiny rather than superior security engineering. The Arris/Technicolor gateways used by Comcast, Cox, and AT&T have been extensively studied by security researchers (notably the Bastille Research CableTap disclosures), while T-Mobile's locked-down Arcadyan/Nokia devices have received less public auditing.

4. ISP-Managed Security Suites Are Getting Better

Comcast's xFi CyberSecure, AT&T's ActiveArmor, Cox's Advanced Security, CenturyLink's Secure WiFi, and Spectrum's Security Shield all represent meaningful improvements in consumer network security. These cloud-managed services provide malware blocking, phishing protection, and device behavior monitoring that would have required a dedicated security appliance just a few years ago. However, they all operate at the network level and cannot replace device-level security (antivirus, OS patches, etc.). Notably, Optimum charges $5/mo for its Advanced Security add-on, while every other ISP in this study includes security features at no extra cost.

5. The Sagemcom/Arris Vendor Risk Is Significant

Three of the bottom four ISPs (Optimum, Spectrum, and CenturyLink) use equipment from vendors with serious CVE histories. Sagemcom has a CVSS 9.8 unauthenticated buffer overflow (CVE-2021-3304) on its F@st 3686 line, plus session timeout and Broadcom cable modem buffer overflow CVEs. Zyxel has a CVSS 9.8 hardcoded credential vulnerability (CVE-2020-29583) and a CISA KEV-listed command injection (CVE-2024-40891). Arris has the muhttpd path traversal (CVE-2022-31793) affecting AT&T gateways. When your ISP chooses your equipment, you inherit their vendor's security track record.

6. The muhttpd Vulnerability Remains the Most Concerning Finding

CVE-2022-31793, affecting AT&T's Arris-derived gateways, is particularly alarming because the underlying muhttpd web server vulnerability had existed since 2006 — 16 years before it was publicly disclosed. This means millions of AT&T gateways were vulnerable to unauthenticated root-level file reads for over a decade. While patched after disclosure, this illustrates the risk of ISP-managed firmware: vulnerabilities can persist for years without independent auditing.

Recommendations

If you're a Comcast Xfinity customer

You have the best default security posture of any ISP in this study. Keep xFi CyberSecure enabled, use the Xfinity app to review connected devices regularly, and set your firewall to Medium or High. If you have advanced security needs (IoT isolation, custom VLANs, VPN routing), enable bridge mode and use your own router.

If you're a Frontier Fiber customer

Your eero mesh system is the most flexible ISP equipment in this study. If you have eero Business, configure up to 4 separate networks to isolate IoT devices, guest devices, and work equipment. If you need even more control, connect your own router directly to the ONT — no ISP gateway required. Consider subscribing to Wi-Fi Security Plus for VPN, ad blocking, and enhanced threat protection. Keep eero auto-updates enabled to ensure CVE-2023-5324 and future vulnerabilities are patched.

If you're a Verizon Fios customer

Your gateway has the best firewall in the study. Ensure your G3100 or CR1000A is running the latest firmware. Enable Home Network Protection and configure content filtering if you have children. If you're still using a G1100, request an upgrade — the legacy CVEs have been patched, but the hardware is aging. Bridge mode is available if you need VLAN isolation.

If you're a T-Mobile 5G customer

Your gateway has a clean CVE record, but the limited feature set means you should strongly consider enabling bridge mode (available on the KVD21 via the T-Life app) and using your own router. This gives you VLAN segmentation, a customizable firewall, and advanced device management that T-Mobile's locked-down gateway doesn't offer. If you have the Nokia 5G21, Bitdefender cybersecurity is included.

If you're a Cox Communications customer

Keep Panoramic WiFi Advanced Security enabled and use the Cox WiFi app for device management. If you have a legacy TG1682 gateway, request an upgrade to the CGM4331 (WiFi 6) — the legacy CVEs are a risk. Bridge mode is available if you need VLAN isolation or want to use your own router. Cox also supports customer-owned modems, which gives you full control over your network equipment.

If you're an AT&T customer

Ensure your BGW320 or BGW210 has been updated to patch CVE-2022-31793 (automatic updates should handle this). Enable ActiveArmor via the Smart Home Manager app. Since AT&T doesn't offer true bridge mode, use IP Passthrough to forward your public IP to your own router — it's not perfect, but it's the best option available. Disable the BGW's WiFi radios if you're using your own access points.

If you're a CenturyLink/Lumen customer

If you have a C3000Z (Zyxel), consider upgrading to the C4000 series (Greenwave) to reduce Zyxel vendor risk. Enable Secure WiFi and use the My CenturyLink app for device groups and content controls. The C3000Z supports transparent bridge mode — use it with your own router for VLAN segmentation and a customizable firewall. Be aware that Zyxel has had CISA KEV-listed vulnerabilities on its DSL CPE product line.

If you're a Spectrum customer

If you have a Sagemcom F@st 5280 (RAC2V1S), request an upgrade to the WiFi 6E or WiFi 7 router — the CVE-2020-24034 privilege escalation is a serious risk. Keep Security Shield enabled and use the My Spectrum app for device management. Spectrum's limited bridge mode support means you may need to purchase your own modem and router to get full control over your network security.

If you're an Optimum/Altice customer

You have the most restrictive ISP in this study. The gateway's web interface is locked, NAT cannot be disabled, and bridge mode is effectively unavailable. If you need network segmentation or a customizable firewall, your only option is to purchase your own DOCSIS 3.1 modem (Optimum allows customer-owned modems) and use your own router. If you subscribe to Advanced Security ($5/mo), be aware that it's DNS-based and explicitly does not protect against inbound network attacks.

Universal Recommendation: Regardless of your ISP, the single most impactful security upgrade you can make is to use bridge mode (or IP Passthrough) with your own router that supports VLAN network segmentation. This isolates your IoT devices from your computers and phones, gives you a real firewall you can configure, and removes your dependence on ISP-managed firmware updates. See our Network Defense Hub for router recommendations and setup guides.

Is Your Network Secure?

Get a professional network security assessment from AIMF Security Services. We'll audit your home or business network, identify vulnerabilities in your router and connected devices, and provide a prioritized remediation plan.

Sources & References

  1. NIST National Vulnerability Database (NVD) — CVE-2022-31793, CVE-2020-24034, CVE-2020-29583, CVE-2024-40891, CVE-2020-29299, CVE-2023-5324, CVE-2021-3304, CVE-2024-1623, CVE-2019-19494, CVE-2026-31195, CVE-2019-3914/3915/3916, CVE-2017-9490/9476/9487/16836, CVE-2018-10989/10990/15907, CVE-2016-7454, CVE-2024-28089, CVE-2025-44179, CVE-2025-63354, CVE-2023-30602 — nvd.nist.gov
  2. Derek Abdine, "Arris Router Critical Vulnerability Advisory" (2022) — derekabdine.com
  3. Tenable Research, "Verizon Fios Quantum Gateway Routers Patched for Multiple Vulnerabilities" (2019) — tenable.com
  4. Bastille Research, CableTap Vulnerability Disclosures — github.com/BastilleResearch
  5. Comcast Xfinity, "xFi CyberSecure" support documentation — xfinity.com
  6. AT&T, "Smart Home Manager" and "ActiveArmor" support documentation — att.com
  7. Verizon, Fios Router G3100/CR1000A User Guides — verizon.com
  8. Spectrum, "Advanced WiFi" and WiFi 7 Router User Guide — spectrum.com
  9. T-Mobile, "Arcadyan KVD21 Gateway" and "Nokia 5G21 Gateway" support pages — t-mobile.com
  10. Cox Communications, "Panoramic WiFi" and "Advanced Security" support documentation — cox.com
  11. CenturyLink, "Secure WiFi" and "C4000/C3000Z Modem User Guides" — centurylink.com
  12. Frontier, "Wi-Fi Security" and "eero Setup Guide" — frontier.com
  13. eero, "Advanced Features" support documentation — eero.com
  14. Optimum, "Advanced Security" product page and subscriber portal guide — optimum.com
  15. CISA Known Exploited Vulnerabilities Catalog — CVE-2024-40891 (Zyxel DSL CPE) — cisa.gov
  16. FCC Equipment Authorization filings (XB10: P27XB10, KVD21, G4AR: RAXTMOG4AR, CGM4141: G95CGM414X) — fccid.io
  17. ismyroutersafe.com, Verizon CR1000A Security Assessment — ismyroutersafe.com
  18. DSLReports, Spectrum Branded Equipment Guide — dslreports.com
  19. nomis, "eeroOS Ethernet Interface DoS Vulnerability (CVE-2023-5324)" — github.com/nomis
  20. Zyxel Security Advisory, "Command Injection and Insecure Default Credentials in Legacy DSL CPE" (2025) — zyxel.com

Research conducted by AIMF Security Services, September 2026. This research paper is provided for informational purposes only and does not constitute professional security advice. ISP gateway deployments vary by region and may change over time. Verify your specific equipment model and firmware version with your ISP.

Full Scorecard — Full Size

Feature Comparison Matrix — Full Size