Unpatched UPnP hole leaves Calix homes open
An unpatched vulnerability in Calix GS7 XGS GS5239XG residential routers lets remote, unauthenticated attackers create port-forwarding rules that expose local devices to the public internet. It’s tracked as CVE-2026-75501, described as a missing authentication issue in EXOS/6.6.47 firmware, and as of the public disclosure there is still no patch.
Security researcher Brian Khan Quintana found it, tried to notify the vendor on June 7 with no success, and eventually Carnegie Mellon CERT Coordination Center coordinated the public disclosure. That’s the headline. The detail is worse.
Calix is a major player in U.S. broadband. The company works with carriers such as Cox Communications, Brightspeed, ALLO, CityFibre and Conexon. Millions of homes sit behind those gateways. When a bug lives on the WAN interface and requires zero authentication, it’s not a lab curiosity.
How the disclosure unfolded
Quintana discovered the flaw in Calix’s implementation of MiniUPnPd. After the June 7 notification attempt went unanswered, he reported to CERT/CC. CERT/CC tried repeatedly to contact the vendor and got no response. They coordinated a public disclosure, and Quintana published the technical findings.
BleepingComputer covered the issue on August 24, 2026, by Bill Toulas. Calix was contacted for comment before publication and did not reply. On August 28, a spokesperson sent a statement: “We conducted our own investigation immediately upon becoming aware of the public report and have determined through testing and analysis that existing network security controls in deployed systems prevent exploitation of the reported attack scenario.”
The researcher released a proof of concept HTTP/SOAP request that shows how the control endpoint can be used remotely. That’s documented on drkq.github.io.
The hardware in question
The affected model is GS5239XG, also marketed as GigaSpire 7u10txg. It’s a new premium gateway that bundles Wi-Fi 7 with an integrated XGS-PON fiber terminal. It’s the kind of box ISPs hand out as future-proof fiber hardware, and many customers never open the admin UI after setup.
The vulnerability is tied to EXOS/6.6.47 firmware. CERT/CC warns the device exposes the MiniUPnPd control endpoint on the WAN interface on TCP port 5000 without access controls.
In affected firmware, the router binds its UPnP WANIPConnection SOAP service to the public WAN interface on TCP port 5000. That’s the core misconfiguration. UPnP is meant for devices behind NAT to negotiate openings locally, not to accept commands from the open internet.
What’s exposed on port 5000
Because the control endpoint is public and unauthenticated, an attacker on the internet can send SOAP requests to add, delete or enumerate port mappings, or to query the external IP address.
Quintana puts it plainly: “One unauthenticated request from anywhere in the world is enough to open a permanent hole through the router’s firewall to any device inside the house. No password. No prompt. Nothing on screen. The rule survives a reboot,”
That bypasses NAT and firewall protections. Internal cameras, network-attached storage, administrative interfaces and IoT appliances all become reachable if an attacker points a mapping at them. The router is effectively instructing itself to forward external traffic inward based on a request it never checks.
What an attacker can actually do
The researcher validated the issue by sending external requests that created a port mapping revealing an internal address. A mapping configured with no expiration stayed active after the router was power-cycled.
Exploitation lets an attacker:
Create arbitrary port-forwarding rules Delete existing mappings Enumerate the router’s current mappings Retrieve its public IP address
The proof of concept is a straightforward HTTP/SOAP request. It practically means anyone on the internet can instruct a vulnerable Calix router to forward traffic from a public-facing port to a chosen device on the home network.
No credentials are required. No user interaction happens. The change is silent and remote.
Why the mapping sticks around
Persistence is what makes this nasty. The mapping survives a reboot and has no expiration in the tested configuration. You can power-cycle the gateway and the hole is still there.
For customers who never log into Advanced settings, the exposure is invisible. There’s no on-screen prompt, no log entry most users would see, and no authentication challenge for the remote request. The router will happily keep forwarding.
The NAT bypass is complete. The firewall, which normally hides the LAN, is now punched through by the router itself based on an unauthenticated command.
Mitigation without a patch
There is no fix for CVE-2026-75501 yet. Quintana recommends disabling UPnP through the admin interface: Advanced → Security → UPnP.
He acknowledges the trade-off. This disables automatic port opening that some games rely on, but manual port setup remains an option. If a specific port needs to be open, the user can create it manually and control it.
CERT/CC adds that the setting might be locked in some deployments, and users who can’t change it should contact their ISP to request deactivation. That’s the practical path for most people who rent the gateway and don’t have admin rights.
Until a firmware update arrives, turning UPnP off is the only user-controllable mitigation. The researcher notes the workaround is imperfect but reduces attack surface immediately.
What Calix said so far
Before publication, BleepingComputer reached out for comment on the flaw, affected models and a possible patch. No reply came before the article went live.
The August 28 update from a Calix spokesperson said: “We conducted our own investigation immediately upon becoming aware of the public report and have determined through testing and analysis that existing network security controls in deployed systems prevent exploitation of the reported attack scenario.”
No patch timeline was provided. CERT/CC’s advisory and the researcher’s testing describe unauthenticated SOAP access on the WAN side, which directly contradicts the claim for the configurations examined.
Risk to ISP customers
The GS5239XG is marketed as a premium gateway. Customers often assume the ISP-managed hardware is secure by default. This flaw undermines that assumption.
If an ISP has deployed the device with UPnP enabled and no network-level block on TCP 5000, the control plane is reachable from the internet. That applies whether the customer knows the password or not. The vulnerability is on the WAN side, so it bypasses the customer’s internal security entirely.
Carriers like Cox Communications, Brightspeed, ALLO, CityFibre and Conexon were mentioned in the coverage as Calix customers. The scale of potential exposure depends on how many units ship with EXOS/6.6.47 and how many have UPnP exposed.
Bottom line for users
This is a home-router class problem with real teeth. Thousands of home and business networks ride on Calix GS7 XGS gear, and an unauthenticated internet-facing UPnP control plane is exactly the kind of misconfiguration that turns a router into a backdoor.
Until Calix ships a firmware update, the most reliable defense is turning off UPnP completely in the router’s administrative panel. If the option is locked by the ISP, call and ask for it to be deactivated. It’s an annoying conversation, but it’s cheaper than explaining a compromised NAS to a family or a client.
Keep an eye on firmware notices from your provider. When a patch lands, install it promptly. In the meantime, assume the control endpoint is reachable and act accordingly.