An unpatched vulnerability in Calix's GS7 XGS (GS5239XG) residential routers lets remote unauthenticated attackers create port‑forwarding rules. The flaw bypasses NAT, exposing cameras, NAS and IoT devices to the public internet.

  • CVE‑2026‑75501 in Calix GS7 XGS routers permits unauthenticated port‑forwarding.
  • Attackers can bypass NAT and expose internal devices without any password.
  • No vendor patch is available; disabling UPnP is the recommended mitigation.

Technical Details of the Vulnerability

The Calix GS7 XGS (GS5239XG) gateway, deployed by major US broadband providers, runs EXOS/6.6.47 firmware that unintentionally exposes the MiniUPnPd control endpoint on the WAN interface at TCP port 5000 without any access controls. This is cataloged as CVE‑2026‑75501.

Discovery and Public Disclosure

Security researcher Brian Khan Quintana first reported the issue to Calix on June 7, but received no response. He escalated the matter to the Carnegie Mellon CERT Coordination Center (CERT/CC), which coordinated a public disclosure after multiple unanswered outreach attempts.

What an Attacker Can Do

Once the endpoint is reachable, an attacker on the open internet can send unauthenticated SOAP requests to add, delete, or enumerate port mappings, and even query the router’s external IP address. This effectively bypasses the router’s NAT and firewall, exposing internal cameras, network‑attached storage, admin panels, and IoT appliances.

Impact on Devices and Users

The affected model is also sold as the GigaSpire 7u10txg**, a premium gateway combining Wi‑Fi 7 with an integrated XGS‑PON fiber terminal. A single unauthenticated request can create a permanent firewall hole that survives reboots.

Mitigation Recommendations

Because no vendor‑issued patch exists, CERT/CC advises users to disable UPnP via the router’s administrative UI (Advanced → Security → UPnP). If the setting is locked, customers should contact their ISP to request deactivation.

Vendor Response and Outlook

BozokMedia analysis shows Calix has not yet commented on a remediation timeline. In the interim, users are urged to employ network segmentation, strict firewall rules, and monitor for unexpected port‑forwarding entries.

Why This Matters

This flaw illustrates how a single exposed service can jeopardize millions of home networks, turning a convenience feature into a massive attack surface. The risk extends beyond large ISPs to any subscriber using the vulnerable hardware.

"An open UPnP endpoint is a silent backdoor; once exploited, it gives attackers direct pathways into private LANs," notes cyber‑security analyst Dr. Maya Patel.
Did You Know?: UPnP was originally designed in 1999 to simplify device discovery, but many routers still ship with the feature enabled by default without proper authentication.

Frequently Asked Questions

Is there a patch available for CVE‑2026‑75501?
No official fix has been released by Calix yet. Disabling UPnP is the only immediate mitigation.

Which Calix models are affected?
The vulnerability affects the GS7 XGS (GS5239XG) and its re‑branded GigaSpire 7u10txg units running EXOS/6.6.47 firmware.