Unpatched Calix Router Vulnerability Lets Hackers Bypass NAT and Expose Internal Devices
An unpatched security vulnerability in Calix GS7 XGS residential routers allows remote, unauthenticated attackers to create port-forwarding rules and expose devices on a user’s local network to the public Internet.
Tracked as CVE-2026-75501, the flaw is caused by missing authentication in devices running EXOS/6.6.47 firmware. The vulnerability affects Calix GS5239XG gateways used by several broadband providers in the United States.
Security researcher Brian Khan Quintana discovered the issue and reported it to the Carnegie Mellon University CERT Coordination Center on June 7, following unsuccessful attempts to contact Calix.
After receiving no response from the vendor despite multiple contact attempts, CERT/CC coordinated a public disclosure, and Quintana published technical details about the vulnerability.
Calix is a major vendor in the U.S. broadband market and partners with providers including Cox Communications, Brightspeed, ALLO, CityFibre, and Conexon.
The affected GS5239XG model is sold as the GigaSpire 7u10txg. The premium gateway combines Wi-Fi 7 connectivity with an integrated XGS-PON fiber terminal.
CVE-2026-75501 exists because the router exposes a MiniUPnPd control endpoint on the WAN interface over TCP port 5000 without proper access controls.
“In affected firmware versions, the router binds the UPnP WANIPConnection SOAP service to the public WAN interface on TCP port 5000,” CERT/CC warns.
This configuration allows remote attackers to send unauthenticated SOAP requests to add, remove, or list port mappings and retrieve the router’s external IP address over the Internet.
By abusing the flaw, attackers can bypass network address translation (NAT) and firewall protections to expose internal devices, including security cameras, network-attached storage (NAS) systems, management interfaces, and other Internet of Things (IoT) appliances.
“One unauthenticated request from anywhere in the world is enough to penetrate your router’s firewall and punch a permanent hole in every device in your home. No passwords, no prompts, nothing on the screen. Rules persist across reboots,” Quintana says.
According to the researchers, attackers can use the vulnerability to perform the following actions:
- Create arbitrary port-forwarding rules
- Delete existing port mappings
- Enumerate the router’s current port mappings
- Retrieve the router’s public IP address
Quintana validated the issue by sending a request from outside his home network to create a port mapping that exposed internal addresses. Port mappings created without an expiration time remained active even after the router was power-cycled.

Source: drkq.github.io
In practice, this means that anyone on the Internet could instruct a vulnerable Calix router to forward traffic from public-facing ports to selected devices inside a victim’s home network.
Because no patch is currently available for CVE-2026-75501, Quintana recommends that users of affected devices disable UPnP through the router’s management interface by navigating to Details → Security → UPnP.
Disabling UPnP may prevent some games and applications from automatically opening the ports they need. However, users can still create specific port-forwarding rules manually when necessary.
CERT/CC notes that some Internet service providers may lock these settings. Users who cannot disable UPnP should contact their ISP and request that the feature be deactivated or that a firmware update be provided.
BleepingComputer contacted Calix for comment about the vulnerability, the affected router models, and whether a security patch will be released. The company had not responded at the time of publication.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




