A serious unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers allows remote, unauthenticated attackers to create port-forwarding rules that expose devices on a local network to the public internet. The flaw, tracked as CVE-2026-75501, stems from a missing authentication issue affecting routers running EXOS/6.6.47 firmware. Security