Calix Router Flaw Exposes Home Devices To Public Internet
An unpatched Calix GS7 XGS router flaw lets unauthenticated attackers create port-forwarding rules that can expose devices inside broadband customers' home networks.

An unpatched flaw in Calix GS7 XGS residential routers can let remote attackers create port-forwarding rules from the public internet, BleepingComputer reported, exposing internal devices behind broadband customers' home firewalls.
The issue is tracked as CVE-2026-75501 and affects devices running EXOS/6.6.47 firmware.
The GS5239XG model, also marketed as the GigaSpire 7u10txg, combines Wi-Fi 7 with an integrated XGS-PON fibre terminal and is used in broadband deployments tied to providers including Cox Communications, Brightspeed, ALLO, CityFibre and Conexon.
WAN Endpoint Opens A Control Path
The vulnerability comes from a MiniUPnPd control endpoint exposed on the WAN interface over TCP port 5000 without access controls.
CERT/CC warned that affected firmware binds the router's UPnP WANIPConnection SOAP service to the public WAN interface, allowing unauthenticated SOAP requests to add, delete or enumerate port mappings or query the external IP address.
That control path bypasses the normal protection customers expect from Network Address Translation and firewall rules.
Cameras, network-attached storage devices, administrative interfaces and IoT appliances can be placed on public-facing ports if the router accepts a malicious mapping request.
Researcher Found Persistent Mapping
Security researcher Brian Khan Quintana discovered the flaw, tried to notify Calix on June 7 and then sent the case to the Carnegie Mellon CERT Coordination Center after receiving no response.
CERT/CC coordinated public disclosure after multiple contact attempts, while Quintana published technical details.
Quintana described the risk as a single unauthenticated internet request creating a lasting firewall opening to a device inside the home, without a password prompt or visible warning to the user.
His test sent requests from outside the home network to create a port mapping to an internal address.
A mapping configured without an expiration remained active after the router was power-cycled, showing that the exposure can persist beyond a simple restart.
Users Have A Workaround, Not A Patch
No fix is available for CVE-2026-75501.
Quintana recommends disabling UPnP in the administrative interface under Advanced, Security and UPnP, though the workaround can affect games and other applications that rely on automatic port opening.
CERT/CC notes that some users may find the setting locked by their internet service provider.
Those customers need to ask the provider to disable UPnP, while Calix has not provided public answers on affected models or a patch timeline.

















