Find notable cyber news and cases, enriched with sources, timelines, and signals.

Calix GS7 XGS (GS5239XG) missing-authentication UPnP WAN bypass (CVE-2026-75501)

Vulnerability
First reported
Last updated
Happening score
H score 15
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-75501 exposes Calix GS7 XGS (GS5239XG) residential routers to unauthenticated WAN UPnP port-forwarding, creating a path to bypass NAT and firewall protections. The flaw affects devices running EXOS/6.6.47 firmware and can let remote attackers open a path from the public internet to internal devices. No vendor fix is available, so users are being told to disable UPnP or ask their ISP to do so.

Timeline

  1. 25.08.2026 00:14 2 articles · 1h ago

    CERT/CC coordinates public disclosure of the Calix router flaw

    Technical Analysis Update

    CERT/CC coordinated a public disclosure of CVE-2026-75501, and Quintana published technical details showing that Calix GS7 XGS (GS5239XG) routers running EXOS/6.6.47 firmware expose the MiniUPnPd control endpoint on TCP port 5000 over the WAN without access controls, allowing unauthenticated SOAP requests to add, delete, or enumerate port mappings and bypass NAT and firewall protections; because no fix is available, users are told to disable UPnP or ask their ISP to do so.

    Show sources