Unpatched Calix router flaw lets attackers bypass NAT to expose internal devices
This digest was compiled by AI from multiple sources — links to the originals are below.

An unpatched vulnerability in Calix GS7 XGS residential routers allows remote attackers to create port-forwarding rules that expose internal devices to the public internet. Security researcher Brian Khan Quintana discovered the flaw and reported it to CERT/CC after the vendor failed to respond. The issue affects devices running EXOS/6.6.47 firmware and has no available fix.
Key Facts
- The vulnerability is tracked as CVE-2026-75501 and affects Calix GS5239XG routers running EXOS/6.6.47 firmware.
- The flaw allows unauthenticated attackers to send SOAP requests to TCP port 5000 on the WAN interface to add, delete, or enumerate port mappings.
- Security researcher Brian Khan Quintana reported the flaw to CERT/CC on June 7 after Calix did not respond to his initial notification.
- Calix works with major U.S. broadband providers including Cox Communications, Brightspeed, ALLO, CityFibre, and Conexon.
- Quintana recommends users disable UPnP via the administrative interface (Advanced → Security → UPnP) as a mitigation.
Vulnerability Details
CVE-2026-75501 is a missing authentication issue in the MiniUPnPd control endpoint exposed on the WAN interface at TCP port 5000. CERT/CC warns that affected firmware versions bind the UPnP WANIPConnection SOAP service to the public WAN interface without access controls. An attacker can send unauthenticated SOAP requests to add, delete, or enumerate port mappings, or query the external IP address. The flaw bypasses the router's NAT and firewall protections, exposing internal cameras, NAS devices, administrative interfaces, and IoT appliances.
Researcher Findings
Quintana demonstrated that a single unauthenticated request from outside the home network could create a permanent port-forwarding rule that survives a reboot. He tested the vulnerability by sending requests from outside his home network to expose an internal address, and the mapping remained active after a power cycle. The researcher published technical details and a proof-of-concept HTTP/SOAP request after CERT/CC coordinated public disclosure.
Affected Devices and Mitigation
The affected model GS5239XG is also marketed as the GigaSpire 7u10txg, a premium gateway combining Wi-Fi 7 and XGS-PON fiber terminal. Calix is a significant vendor in the U.S. broadband-provider market, serving large entities such as Cox Communications, Brightspeed, ALLO, CityFibre, and Conexon. With no fix available for CVE-2026-75501, Quintana recommends users disable UPnP through the administrative interface at Advanced → Security → UPnP.
2 sources
Unpatched Calix router flaw lets attackers bypass NAT to expose internal devices




