Calix GS7 XGS (GS5239XG) missing-authentication UPnP WAN bypass (CVE-2026-75501)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-75501 exposes Calix GS7 XGS (GS5239XG) residential routers to unauthenticated WAN UPnP port-forwarding, creating a path to bypass NAT and firewall protections. The flaw affects devices running EXOS/6.6.47 firmware and can let remote attackers open a path from the public internet to internal devices. No vendor fix is available, so users are being told to disable UPnP or ask their ISP to do so.
Timeline
-
25.08.2026 00:14 2 articles · 1h ago
CERT/CC coordinates public disclosure of the Calix router flaw
Technical Analysis UpdateCERT/CC coordinated a public disclosure of CVE-2026-75501, and Quintana published technical details showing that Calix GS7 XGS (GS5239XG) routers running EXOS/6.6.47 firmware expose the MiniUPnPd control endpoint on TCP port 5000 over the WAN without access controls, allowing unauthenticated SOAP requests to add, delete, or enumerate port mappings and bypass NAT and firewall protections; because no fix is available, users are told to disable UPnP or ask their ISP to do so.
Show sources
- Unpatched Calix flaw lets hackers bypass NAT to expose internal devices — www.bleepingcomputer.com — 25.08.2026 00:14
- Unpatched Calix flaw lets hackers bypass NAT to expose internal devices — www.bleepingcomputer.com — 25.08.2026 00:14
-
07.06.2026 03:00 1 articles · 2mo ago
Quintana reports Calix router flaw to CERT/CC
Initial DisclosureSecurity researcher Brian Khan Quintana tried to notify Calix on June 7 and, after no success, reported CVE-2026-75501 to the Carnegie Mellon CERT Coordination Center.
Show sources
- Unpatched Calix flaw lets hackers bypass NAT to expose internal devices — www.bleepingcomputer.com — 25.08.2026 00:14