Calix GS7 XGS (GS5239XG) missing-authentication UPnP WAN bypass (CVE-2026-75501)
Vulnerability
Updated: 25.08.2026 00:14
· First: 25.08.2026 00:14
· 📰 1 src / 1 articles
· H score: 15
CVE-2026-75501 exposes Calix GS7 XGS (GS5239XG) residential routers to unauthenticated WAN UPnP port-forwarding, creating a path to bypass NAT and firewall protections. The flaw affects devices running EXOS/6.6.47 firmware and can let remote attackers open a path from the public internet to internal devices. No vendor fix is available, so users are being told to disable UPnP or ask their ISP to do so.