Description

A critical vulnerability in Calix GS7 XGS residential routers could allow remote, unauthenticated attackers to bypass Network Address Translation (NAT) and expose devices inside private home networks to the public internet. The flaw, tracked as CVE-2026-75501, affects the Calix GS5239XG router running EXOS/6.6.47 firmware. The affected device is also marketed as the GigaSpire 7u10txg and is used by several broadband providers in the United States. The vulnerability is particularly serious because attackers do not need a password or local network access to exploit it. The problem is caused by the router exposing its MiniUPnPd control endpoint on the WAN interface through TCP port 5000 without proper access controls. An attacker on the internet can send unauthenticated requests to create, remove, or view port-forwarding rules. This effectively allows the attacker to create a path through the router's NAT and firewall to a device inside the victim's network. Internal security cameras, NAS systems, IoT devices, administrative interfaces, and other network-connected equipment could therefore become reachable from the internet. Testing by the security researcher showed that a port-forwarding rule created through the flaw could remain active even after the router was restarted. At the time of publication, Calix had not released a security update for the vulnerability. Users with affected routers are advised to disable UPnP through the router's administrative interface, although the setting may be locked by some internet service providers. In such cases, users should contact their ISP and request that UPnP be disabled. Organizations and service providers should identify affected devices, restrict unnecessary internet exposure, monitor for unexpected port-forwarding changes, and review internal devices that may have been exposed. Because the flaw can be exploited remotely without authentication, disabling the vulnerable functionality is currently the primary mitigation until a vendor patch becomes available.