search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability

Vulnerability Note VU#756733

Original Release Date: 2026-08-21 | Last Revised: 2026-09-09

Overview

The Calix GS7 XGS GS5239XG router running firmware EXOS/6.6.47 contains a missing authentication vulnerability that exposes its UPnP (Universal Plug and Play) WANIPConnection service on the public WAN interface.

Description

Calix GS7 XGS GS5239XG is a residential gateway that provides routing, NAT, and firewall functionality for home networks. The device includes the Universal Plug and Play (UPnP) service implemented via MiniUPnPd 2.3.7, a lightweight software program that provides features such as automatic port forwarding for applications and devices on the LAN. By default, the UPnP service is exposed on the device’s WAN interface and does not require authentication.

CVE-2026-75501 In affected firmware versions, the router binds its UPnP WANIPConnection SOAP service to the public WAN interface on TCP port 5000. Because the service does not require authentication when accepting SOAP requests, a remote attacker can obtain full access to the router’s critical UPnP functions including adding, deleting, and enumerating NAT port mappings.

Impact

CVE-2026-75501 enables an unauthenticated, remote attacker to remotely query and manipulate existing NAT mappings. By exploiting this vulnerability to create arbitrary port-forwarding rules on the router, an attacker can bypass NAT and firewall protections, exposing internal LAN devices to the public internet. Because the Calix router is typically provisioned with its default UPnP-enabled configuration, this issue poses significant risk to residential users with network-connected internal devices such as security cameras, network-attached storage (NAS), and other IoT appliances.

Solution

Unfortunately, the CERT/CC was unable to reach Calix to coordinate this vulnerability. Until a vendor patch is available, users can reduce exposure by disabling UPnP on the router’s administrative interface. If the UPnP setting is unavailable or locked, it may be necessary to contact your ISP to request its deactivation at the carrier level. Alternatively, filtering inbound traffic to TCP port 5000, either via the router itself, a secondary firewall, or through your ISP, can prevent external hosts from reaching the WANIPConnection service.

Acknowledgements

Thanks to Brian Khan Quintana for researching and reporting this vulnerability. This document was written by Molly Jaconski.

Vendor Information

756733
 

Calix Not Affected

Notified:  2026-07-07 Updated: 2026-09-09

Statement Date:   September 09, 2026

CVE-2026-75501 Not Affected

Vendor Statement

Calix has completed an initial investigation of the vulnerability described in VU#756733 and CVE-2026-75501. To date, Calix has been unable to reproduce the reported behavior. On our GS5239XG gateways running standard EXOS firmware, an unauthenticated request directed from outside the network to the UPnP WANIPConnection service does not reach that service, because the default WAN firewall drops inbound traffic to TCP port 5000 before it is delivered to the UPnP daemon. Calix sought to reproduce the result under the conditions specified in the public writeup. The test host was placed outside the gateway, on a routable public address, with no intermediary NAT or firewall that would absorb the inbound packet. The evaluation followed the exact sequence described in VU#756733: a GET request for rootDesc.xml from an off-network host, followed by an unauthenticated SOAP AddPortMapping call. Testing was conducted across multiple units and models under multiple firmware releases, against both laboratory gateways and a live gateway assigned a public IP address. Calix engineering development and test teams executed multiple scenarios; all security controls performed as designed. The outcome, that WAN access is blocked, was consistent across every attempt.

Calix does not dispute that the researcher observed the behavior described in the published writeup. Rather, on the firmware and configuration Calix distributes, the remote access path characterized in the report is not open, and Calix has not yet identified conditions on its own systems under which it becomes open.

Based on the analysis and testing completed to date, Calix has confirmed no customer-impacting exposure on deployed systems and has identified no affected customer deployments. No customer configuration change, software update, or corrective action is required at this time.


Other Information

CVE IDs: CVE-2026-75501
API URL: VINCE JSON | CSAF
Date Public: 2026-08-21
Date First Published: 2026-08-21
Date Last Updated: 2026-09-09 17:40 UTC
Document Revision: 2

Sponsored by CISA.