mimile
Back to feed

Unpatched Calix router flaw lets attackers bypass NAT to expose internal devices

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Unpatched Calix router flaw lets attackers bypass NAT to expose internal devices

An unpatched vulnerability in Calix GS7 XGS residential routers allows remote attackers to create port-forwarding rules that expose internal devices to the public internet. Security researcher Brian Khan Quintana discovered the flaw and reported it to CERT/CC after the vendor failed to respond. The issue affects devices running EXOS/6.6.47 firmware and has no available fix.

Key Facts

  • The vulnerability is tracked as CVE-2026-75501 and affects Calix GS5239XG routers running EXOS/6.6.47 firmware.
  • The flaw allows unauthenticated attackers to send SOAP requests to TCP port 5000 on the WAN interface to add, delete, or enumerate port mappings.
  • Security researcher Brian Khan Quintana reported the flaw to CERT/CC on June 7 after Calix did not respond to his initial notification.
  • Calix works with major U.S. broadband providers including Cox Communications, Brightspeed, ALLO, CityFibre, and Conexon.
  • Quintana recommends users disable UPnP via the administrative interface (Advanced → Security → UPnP) as a mitigation.

Vulnerability Details

CVE-2026-75501 is a missing authentication issue in the MiniUPnPd control endpoint exposed on the WAN interface at TCP port 5000. CERT/CC warns that affected firmware versions bind the UPnP WANIPConnection SOAP service to the public WAN interface without access controls. An attacker can send unauthenticated SOAP requests to add, delete, or enumerate port mappings, or query the external IP address. The flaw bypasses the router's NAT and firewall protections, exposing internal cameras, NAS devices, administrative interfaces, and IoT appliances.

Researcher Findings

Quintana demonstrated that a single unauthenticated request from outside the home network could create a permanent port-forwarding rule that survives a reboot. He tested the vulnerability by sending requests from outside his home network to expose an internal address, and the mapping remained active after a power cycle. The researcher published technical details and a proof-of-concept HTTP/SOAP request after CERT/CC coordinated public disclosure.

Affected Devices and Mitigation

The affected model GS5239XG is also marketed as the GigaSpire 7u10txg, a premium gateway combining Wi-Fi 7 and XGS-PON fiber terminal. Calix is a significant vendor in the U.S. broadband-provider market, serving large entities such as Cox Communications, Brightspeed, ALLO, CityFibre, and Conexon. With no fix available for CVE-2026-75501, Quintana recommends users disable UPnP through the administrative interface at Advanced → Security → UPnP.

2 sources

Unpatched Calix router flaw lets attackers bypass NAT to expose internal devices