A critical Calix router vulnerability lets unauthenticated attackers bypass home network protections and expose internal devices to the internet.

The issue affects Calix GS7 XGS routers, model GS5239XG, running EXOS/6.6.47 firmware. Researchers catalogue the flaw as CVE-2026-75501.

Attackers can create port-forwarding rules remotely without a password or local network access.

Exposed UPnP service creates the risk

The router exposes a MiniUPnPd control endpoint through its public WAN interface on TCP port 5000.

Network address translation, known as NAT, normally prevents external systems from directly reaching devices on a local network. However, the exposed service lets attackers bypass that protection.

An attacker can send unauthenticated requests that create, delete or list port-forwarding rules. They can also request the router’s public IP address.

As a result, criminals can direct traffic from the public internet to a chosen device inside a home or business network.

Attackers could expose internal devices

The Calix router vulnerability can put devices behind the firewall at risk.

Attackers could expose security cameras, network-attached storage systems, internet-connected appliances and local administration panels. They may also create a port-forwarding rule that remains active after a reboot.

Researcher Brian Khan Quintana tested the flaw from outside his home network. He created a port mapping that exposed an internal address and survived a power cycle.

A malicious rule can leave a permanent opening in the firewall. The router does not require a password, show a prompt or alert the user when an attacker creates that rule.

Broadband providers supply affected routers

Several US broadband providers use Calix networking equipment. Calix also sells the affected GS5239XG gateway under the GigaSpire 7u10txg name.

The device combines Wi-Fi 7 support with an integrated XGS-PON fibre terminal.

Quintana contacted Calix about the flaw on June 7. After he received no response, he reported it to the CERT Coordination Center. CERT/CC then coordinated the public disclosure.

Calix had not released a security update at the time of publication.

Disable UPnP until Calix releases a fix

Affected users should disable Universal Plug and Play, or UPnP, through the router’s administration interface.

Find the option under:

Advanced → Security → UPnP

UPnP helps games and applications open ports automatically. Turning it off may affect those functions, but users can open necessary ports manually.

Some internet providers lock the UPnP setting. Customers who cannot change it should contact their ISP and ask it to disable UPnP.

The Calix router vulnerability can give attackers direct paths into a private network. Users should install any future firmware update promptly and review their port-forwarding rules for unfamiliar entries.


0 responses to “Unpatched Calix Router Vulnerability Can Expose Home Devices Online”