An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers, identified as CVE-2026-75501, allows remote, unauthenticated attackers to create persistent port-forwarding rules. This critical flaw enables a bypass of Network Address Translation (NAT) and firewall protections, leading to the exposure of internal network devices to the public internet. Security researcher Brian Khan Quintana discovered the vulnerability and, after unsuccessful attempts to contact the vendor, coordinated a public disclosure through the Carnegie Mellon CERT Coordination Center, as reported by BleepingComputer.
Technical Analysis of CVE-2026-75501
The vulnerability, tracked as CVE-2026-75501, is described as a missing authentication issue affecting Calix devices running EXOS/6.6.47 firmware. Specifically, the flaw stems from the router exposing its MiniUPnPd control endpoint on the WAN interface on TCP port 5000 without proper access controls. CERT/CC warns that in affected firmware versions, the router binds its UPnP WANIPConnection SOAP service to the public WAN interface.
This configuration allows any attacker on the public internet to send unauthenticated SOAP requests to the device. These requests can be used to add, delete, or enumerate port mappings, or to query the external IP address of the router. This capability provides a direct pathway for attackers to bypass the router’s NAT and firewall. Quintana’s findings demonstrate that “one unauthenticated request from anywhere in the world is enough to open a permanent hole through the router’s firewall to any device inside the house. No password. No prompt. Nothing on screen. The rule survives a reboot.”
Impact of Calix GS5239XG NAT Bypass
The immediate impact of the Calix GS5239XG NAT bypass is severe. Attackers can leverage this flaw to expose various internal network devices, including IP cameras, Network-Attached Storage (NAS) devices, administrative interfaces for other home network equipment, and IoT appliances, making them directly accessible from the internet. Quintana tested this by creating a port mapping that exposed an internal address, confirming that the mapping remained active even after a router power cycle, allowing persistent access. The affected model, GS5239XG, is also marketed as the GigaSpire 7u10txg, a new, premium gateway device used by significant U.S. broadband providers such as Cox Communications, Brightspeed, ALLO, CityFibre, and Conexon, indicating a wide potential attack surface.
Mitigation and Recommendations for Calix GS7 XGS Users
Given that there is currently no official patch available for CVE-2026-75501, users of vulnerable Calix GS7 XGS routers must take immediate action to protect their networks. The primary recommendation by researcher Brian Khan Quintana is to disable UPnP Calix GS7 XGS through the router’s administrative interface. This setting is typically found under Advanced -> Security -> UPnP. Disabling UPnP prevents automatic port opening, which is a key mechanism for this attack.
While disabling UPnP might affect certain applications or games that rely on automatic port forwarding, specific ports can always be opened manually if necessary. CERT/CC also notes that in some scenarios, the UPnP setting might be locked or inaccessible to the end-user. In such cases, users should contact their Internet Service Provider (ISP) and request the deactivation of UPnP functionality on their Calix router. This will help mitigate the risks associated with CVE-2026-75501 exploitation details until a vendor-issued patch becomes available. Users should monitor official Calix channels for firmware updates addressing this critical vulnerability.