An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet.
The flaw is tracked as CVE-2026-75501 and is described as a missing authentication issue that affects devices running EXOS/6.6.47 firmware.
Security researcher Brian Khan Quintana discovered the flaw and, after trying to notify the vendor on June 7 without success, he reported the vulnerability to the Carnegie Mellon CERT Coordination Center.
Following multiple attempts to contact the vendor and receiving no response, CERT/CC coordinated a public disclosure, and Quintana published the technical details.
Calix is a significant vendor in the US broadband-provider market, working with large entities such as Cox Communications, Brightspeed, ALLO, CityFibre, and Conexon.
The affected model, GS5239XG, is also marketed as the GigaSpire 7u10txg and is a new, premium gateway device that combines Wi-Fi 7 capabilities with an integrated XGS-PON fiber terminal.
The CVE-2026-75501 vulnerability is caused by the device exposing “the MiniUPnPd control endpoint on the WAN interface on TCP port 5000 without access controls.”
“In affected firmware versions, the router binds its UPnP WANIPConnection SOAP service to the public WAN interface on TCP port 5000,” CERT/CC warns.
This allows an attacker on the public web to send the device unauthenticated “SOAP requests to add, delete, or enumerate port mappings, or to query the external IP address.”
This way, hackers can bypass the router’s Network Address Translation (NAT) and firewall protections and expose internal cameras, network-attached storage (NAS) devices, administrative interfaces, and IoT appliances.
“One unauthenticated request from anywhere in the world is enough to open a permanent hole through the router’s firewall to any device inside the house. No password. No prompt. Nothing on screen. The rule survives a reboot,” Quintatna says.
The researcher says that an attacker leveraging the security issue could take the following actions:
Quintana tested the finding by sending requests outside his home network to create a port mapping that exposed an internal address. A mapping configured with no expiration remained active after the router was power-cycled.
This practically means anyone on the internet can instruct vulnerable Calix routers to forward traffic from a public-facing port to a chosen device on the home network.
Given that there’s no fix for CVE-2026-75501, Quintana recommends that users of the vulnerable device disable UPnP through the administrative interface (Advanced → Security → UPnP).
The researcher notes that this workaround disables automatic port opening, which some games rely on, but it’s always possible to open specific ports manually.
CERT/CC also notes that the setting might be locked in some cases, and users who can’t change it should contact their ISP to request the deactivation.
BleepingComputer has contacted Calix for a comment about the flaw, the device models it impacts, and if a patch will be released, but we have not heard back as of publishing.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Check Point warns of SmartConsole zero-day exploited in attacks
South Korea discloses data breach impacting diplomats worldwide
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
American companies have outsourced, H1b’d and AI’d so much there is a serious competency crisis going on. If you go to this company’s site they have 2 options for “Careers”, “Chinese Careers” and “India Careers”. I assert that within the next 5 years or less there will be major failures in large tech companies due to lack of experience and knowledge. You see this already in companies like Microsoft, Verizon, AT&T and others.
Hackers infect Android car head units with proxy botnet malware
ToxicPanda Android malware uses VPN permissions to block Google Play
Microsoft Teams now lets admins block external bots from meetings
Discover how least agency keeps your AI tools capable, controlled, and secure.
See how AI is reshaping email attacks. Download the 2026 Kaseya Email Security Report.
Discover why encryption and key management are critical for modern business.
Signature-based prevention fell to 50%. See what your controls still stop.
Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday.
Protect yourself from data brokers, scammers, and the next data breach with digital identities.
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



