An unpatched security vulnerability in Calix GS7 XGS routers, also known as the GS5239XG or GigaSpire 7u10txg models, allows an attacker on the internet to create port-forwarding rules without logging in, potentially opening a direct path to devices on the home network.
The vulnerability is tracked as CVE-2026-75501 and affects devices running EXOS/6.6.47 firmware. According to details coordinated for publication by Carnegie Mellon University's CERT Coordination Center (CERT/CC), the issue results from exposing the control endpoint for the MiniUPnPd service on the public WAN interface through TCP port 5000, without access controls.
How Can the Flaw Be Exploited?
The exposed interface allows unauthenticated SOAP requests to be sent to the UPnP WANIPConnection service to add, delete, or list port forwards, as well as query the router's external IP address. This can bypass the protection provided by both NAT and the firewall, directing incoming connections from the internet to an address selected by the attacker inside the network.
Security researcher Brian Khan Quintana tested the vulnerability by sending requests from outside his home network to create a port forward to an internal device. He said that the forwarding rule created without an expiration period remained active after the router was powered off and restarted. Potential impacts include exposing surveillance cameras, network-attached storage (NAS) devices, management interfaces, and Internet of Things devices.
According to Quintana, a single unauthenticated request from anywhere on the internet may be enough to create a persistent opening through the router's firewall, without a password or a prompt being shown to the user. Possible operations also include creating arbitrary port-forwarding rules, deleting existing rules, listing current forwards, and obtaining the public IP address.
Disclosure and Lack of a Patch
Quintana discovered the flaw and attempted to report it to Calix on June 7, but received no response, so he turned to CERT/CC. After additional attempts to contact the company without a reply, the center coordinated the public disclosure of the vulnerability, after which the researcher published its technical details.
Several broadband providers in the United States use Calix devices, including Cox Communications, Brightspeed, ALLO, CityFibre, and Conexon. The GS5239XG is a modern, high-end gateway device that combines Wi-Fi 7 capabilities with an integrated XGS-PON fiber terminal.
BleepingComputer contacted Calix for comment on the vulnerability, the affected models, and plans to release a patch, but had not received a response at the time of publication.
What Should Users Do?
Because no fix is available, Quintana and CERT/CC recommend disabling UPnP from the management interface via the path: Advanced → Security → UPnP. This stops ports from being opened automatically, a function that some games may rely on, but specific ports can be opened manually when needed.
CERT/CC notes that the option to disable UPnP may be locked in some cases. When it cannot be changed, users should contact their internet service provider and request that the function be disabled. The practical significance of the news is that the risk requires neither an account nor interaction from the homeowner, while the final scope of affected devices and Calix's plan to release a patch remain open questions requiring clarification from the company.