An unpatched vulnerability in Calix GS7 XGS residential routers, including the GS5239XG model marketed as the GigaSpire 7u10txg, allows remote, unauthenticated attackers to create port-forwarding rules that expose internal network devices to the public internet. The flaw, tracked as CVE-2026-75501, affects devices running EXOS/6.6.47 firmware and is described as a missing authentication issue. Calix supplies these gateways to multiple U.S. broadband providers, including Cox Communications, Brightspeed, ALLO, CityFibre, and Conexon, making the issue relevant to a wide swath of American home networks.

Security researcher Brian Khan Quintana discovered the flaw and first attempted to notify the vendor on June 7 without success. He then reported the vulnerability to the Carnegie Mellon CERT Coordination Center. After multiple failed attempts to contact Calix, CERT/CC coordinated a public disclosure, and Quintana published the technical details. The root cause is that the device exposes the MiniUPnPd control endpoint on the WAN interface on TCP port 5000 without access controls, binding its UPnP WANIPConnection SOAP service to the public-facing side of the router.

This exposure lets anyone on the public web send unauthenticated SOAP requests to add, delete, or enumerate port mappings, and to query the external IP address. By exploiting this, a hacker can bypass the router's Network Address Translation and firewall protections, potentially exposing internal cameras, network-attached storage devices, administrative interfaces, and IoT appliances. Quintana tested the issue by sending requests from outside his home network to create a port mapping that exposed an internal address, and he found that a mapping configured with no expiration remained active even after the router was power-cycled.

In practical terms, any internet user can instruct a vulnerable Calix router to forward traffic from a public-facing port to a chosen device on the home network. Because no patch exists for CVE-2026-75501, Quintana recommends that users disable UPnP through the administrative interface under Advanced Security UPnP. This workaround disables automatic port opening, which some games rely on, but users can still manually open specific ports as needed.

CERT/CC notes that the UPnP setting might be locked in some cases, and users who cannot change it should contact their internet service provider to request deactivation. BleepingComputer reached out to Calix for comment on the flaw, the affected device models, and whether a patch will be released, but the company had not responded by the time of publishing. The vulnerability highlights a broader concern for U.S. broadband customers, as the affected gateway is a premium device combining Wi-Fi 7 capabilities with an integrated XPS-PON fiber terminal, and many ISPs deploy it as the primary home router.

More cybersecurity news from TechManNews.