Calix Router Flaw Punches Through the Customer Edge
BleepingComputer reports that a missing-authentication flaw in Calix GS7 XGS (GS5239XG) residential gateways, tracked as CVE-2026-75501, lets unauthenticated outsiders create port-forwarding rules on devices running EXOS 6.6.47. Security researcher Brian Khan Quintana disclosed it after repeated contact attempts to Calix failed, and CERT/CC coordinated the public release.
The weak point is the router’s MiniUPnPd control service, which is listening on the WAN side of the public internet on TCP 5000 without access controls. That lets a remote user send UPnP (Universal Plug and Play) requests to add, delete, or list mappings, so the gateway can expose cameras, NAS boxes, admin panels, and other LAN devices without stealing any password.
For broadband operators, the trust boundary that NAT and the firewall are supposed to enforce is the part that breaks: a single exposed gateway can make customer-side devices reachable from outside even if the devices themselves were never directly targeted. If EXOS/6.6.47 is widely deployed, the inherited exposure sits behind the router, not just in the router itself.