Unpatched Calix Router Flaw Exposes Home Networks to Remote Attackers
A serious unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers allows remote, unauthenticated attackers to create port-forwarding rules that expose devices on a local network to the public internet. The flaw, tracked as CVE-2026-75501, stems from a missing authentication issue affecting routers running EXOS/6.6.47 firmware. Security researcher Brian Khan Quintana discovers the issue after finding that attempts to notify the vendor on June 7 go unanswered, leading him to report it to the Carnegie Mellon CERT Coordination Center, which coordinates a public disclosure.
Calix serves as a significant vendor in the U.S. broadband market, working with major providers including Cox Communications, Brightspeed, ALLO, CityFibre, and Conexon. The affected model, also marketed as the GigaSpire 7u10txg, is a premium gateway that combines Wi-Fi 7 capabilities with an integrated XGS-PON fiber terminal. The vulnerability arises because the device exposes the MiniUPnPd control endpoint on the WAN interface over TCP port 5000 without access controls, allowing the UPnP WANIPConnection SOAP service to accept requests from the public internet.
Attackers can exploit this by sending unauthenticated SOAP requests to add, delete, or enumerate port mappings, or to query the router's external IP address. This allows them to bypass NAT and firewall protections and expose internal cameras, NAS devices, administrative interfaces, and IoT appliances. Quintana warns that a single unauthenticated request from anywhere in the world is enough to open a permanent hole through the router's firewall to any device inside the home, with no password or prompt required, and the rule survives a reboot.