Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

Vulnerability Exposes Home Network Devices to Public Internet, Leaving Millions at Risk

A critical unpatched flaw in Calix GS7 XGS residential routers has been discovered, allowing hackers to bypass Network Address Translation (NAT) and expose internal devices to the public internet. The vulnerability, tracked as CVE-2026-75501, affects devices running EXOS/6.6.47 firmware and can be exploited by remote attackers without requiring any authentication or credentials.

The affected model, GS5239XG, is a premium gateway device marketed as the GigaSpire 7u10txg, which combines Wi-Fi 7 capabilities with an integrated XGS-PON fiber terminal. Calix routers are used by multiple U.S. broadband providers, including Cox Communications, Brightspeed, and ALLO, among others. This means that millions of households using these devices are potentially at risk.

The vulnerability allows hackers to create port-forwarding rules that can expose local network devices, such as cameras, network-attached storage (NAS) devices, administrative interfaces, and IoT appliances, to the public internet. This can be done through unauthenticated “SOAP requests” sent over TCP port 5000, which is exposed on the WAN interface of affected routers.

According to security researcher Brian Khan Quintana, who discovered the flaw, an attacker can bypass the router’s NAT and firewall protections by sending a single request from anywhere in the world. This can create a permanent hole through the router’s firewall, exposing internal devices without any password or authentication prompt.

Quintana tested the vulnerability by creating a port mapping that exposed an internal address, which remained active even after rebooting the router. This means that hackers can instruct vulnerable Calix routers to forward traffic from a public-facing port to a chosen device on the home network.

Given the severity of this flaw and the fact that there is no fix available yet, Quintana recommends that users disable UPnP through the administrative interface (Advanced → Security → UPnP). This may require contacting the ISP for assistance, as some settings might be locked. Disabling UPnP will prevent automatic port opening, but it’s still possible to open specific ports manually.

The discovery of this vulnerability highlights the importance of keeping firmware up-to-date and being aware of potential security risks in home network devices. Users who are concerned about their safety should consider taking steps to protect their internal devices and contacting their ISP for further assistance.

As a practical takeaway, users should be cautious when using devices that rely on UPnP for automatic port opening, such as online gaming consoles or IoT appliances. Disabling UPnP may require some technical expertise, but it’s a simple step that can significantly reduce the risk of exposing internal devices to hackers.


Source: Bleeping Computer — 2026-08-24