Vulnerability in Calix Routers Exposes Internal Devices to Public Internet, No Fix in Sight
A significant security vulnerability has been discovered in Calix GS7 XGS (GS5239XG) residential routers used by multiple US broadband providers. This flaw allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet, effectively bypassing Network Address Translation (NAT) and firewall protections.
The vulnerability, tracked as CVE-2026-75501, affects devices running EXOS/6.6.47 firmware and is caused by the device exposing a MiniUPnPd control endpoint on the WAN interface without access controls. This allows an attacker to send unauthenticated SOAP requests to add, delete, or enumerate port mappings, or to query the external IP address. With this ability, hackers can create permanent holes in the router’s firewall, granting them access to internal cameras, network-attached storage (NAS) devices, administrative interfaces, and IoT appliances.
The issue was discovered by security researcher Brian Khan Quintana, who attempted to notify Calix on June 7 without success. After coordinating with CERT/CC, Quintana published technical details about the vulnerability. The affected model, GS5239XG, is a new premium gateway device that combines Wi-Fi 7 capabilities with an integrated XGS-PON fiber terminal.
Calix is a significant vendor in the US broadband-provider market, working with large entities such as Cox Communications and Brightspeed. This vulnerability affects users of Calix routers who have not updated their firmware to the latest version. Given that there’s no fix for CVE-2026-75501, Quintana recommends disabling UPnP through the administrative interface (Advanced → Security → UPnP). This workaround may disable automatic port opening, which some games rely on, but it’s always possible to open specific ports manually.
CERT/CC notes that users who can’t change this setting should contact their ISP to request deactivation. It’s essential for users of Calix routers to take immediate action and disable UPnP to prevent potential attacks. As the vulnerability is unpatched, it’s crucial to be cautious and consider disabling UPnP as a temporary measure until a fix becomes available.
In light of this discovery, it’s also essential to remember that prevention scores can hide what happens after initial access. Once attackers have valid credentials, only 37% of their actions are blocked. This vulnerability serves as a reminder of the importance of staying vigilant and taking proactive measures to secure our networks.
Source: Bleeping Computer — 2026-08-24