TL;DR
CVE-2026-75501 is a missing authentication flaw in the Calix GS7 XGS GS5239XG router. Its UPnP service sits exposed on the public WAN interface without any login. Full technical details and proof-of-concept exploit code are now public. As a result, a remote attacker can bypass NAT and firewall protections. No exploitation in the wild has been confirmed yet.
- CVE: CVE-2026-75501
- CVSS: Awaiting analysis
- Product: Calix GS7 XGS (GS5239XG)
- Affected: ≤ Firmware EXOS/6.6.47
- Impact: CVE-2026-75501
- Status: No confirmed exploitation yet
- Action: See vendor advisory
Why This Calix Router Flaw Matters
The Calix GS7 XGS is a residential gateway. It handles routing, NAT, and firewall duties for home networks. This flaw undoes those protections. An attacker can reach internal LAN devices from the open internet. That puts cameras, NAS boxes, and other IoT gear at risk. CERT/CC published the issue as Vulnerability Note VU#756733.
How the Attack Works
The router runs UPnP through MiniUPnPd 2.3.7. By default, it binds the WANIPConnection SOAP service to the public WAN interface on TCP port 5000. However, the service accepts SOAP requests without authentication.
Because no login is required, a remote attacker gains full access to critical UPnP functions. They can add, delete, and enumerate NAT port mappings. By creating arbitrary port-forwarding rules, an attacker can bypass NAT and firewall protections. That step exposes private LAN devices to the wider internet. The researcher’s public write-up documents the flaw and its proof-of-concept code.
Exploitation and Disclosure Status
The details are fully public. Both the CERT/CC note and the researcher’s page describe the flaw openly. The write-up also shares proof-of-concept exploit code. However, no source confirms active exploitation in the wild so far.
Affected Versions
The advisory names the Calix GS7 XGS GS5239XG running firmware EXOS/6.6.47. Devices ship with UPnP enabled by default. Therefore most units carry the risky configuration out of the box.
Patch and Mitigation Steps
No vendor patch exists yet. CERT/CC reports it could not reach Calix to coordinate a fix. In the meantime, disable UPnP on the router’s admin interface. If that setting is locked, ask your ISP to turn it off at the carrier level. You can also filter inbound traffic to TCP port 5000. A secondary firewall or an ISP-level block can stop external access to the service.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.