A missing authentication flaw in Calix GS7 XGS (GS5239XG) routers lets remote attackers create port-forwarding rules and expose home-network devices to the internet without logging in. Security researcher Brian Khan Quintana disclosed CVE-2026-75501 after vendor contact attempts failed, and the current workaround is to disable UPnP or ask the ISP to do so. #Calix #GS5239XG #CVE-2026-75501 #CERTCC #BrianKhanQuintana
Keypoints
- CVE-2026-75501 affects Calix GS7 XGS (GS5239XG) routers running EXOS/6.6.47 firmware.
- The flaw exposes the MiniUPnPd control endpoint on WAN port 5000 without access controls.
- Attackers can add, delete, or enumerate port mappings with unauthenticated SOAP requests.
- The issue can bypass NAT and firewall protections to expose internal devices like cameras and NAS systems.
- No patch is available yet, so users should disable UPnP or contact their ISP for help.