Critical unpatched flaw in Calix routers exposes home networks to internet
A critical, unpatched flaw in Calix Systems’ GS7 XGS (GS5239XG) residential routers allows remote attackers to bypass NAT and expose internal devices on the public internet.
Source: BleepingComputer · August 24, 2026 at 10:53 PM · AI-assisted report
Single-source
KUALA LUMPUR, 25 AUGUST 2026 —
A critical, unpatched flaw in Calix Systems’ GS7 XGS (GS5239XG) residential routers allows remote attackers to bypass NAT and expose internal devices on the public internet.
Market Impact
The vulnerability, tracked as CVE-2026-75501, affects devices running EXOS/6.6.47 firmware. It stems from the router exposing the MiniUPnPd control endpoint on TCP port 5000 without authentication. Security researcher Brian Khan Quintana found that unauthenticated SOAP requests sent to this endpoint can add, delete or enumerate port mappings, or query the external IP address.
“One unauthenticated request from anywhere in the world is enough to open a permanent hole through the router's firewall to any device inside the house,” Quintana said. “No password. No prompt. Nothing on screen. The rule survives a reboot.” He demonstrated the issue by sending requests from outside his home network, creating a port mapping that remained active after the router was power-cycled.
Calix markets the GS5239XG as the GigaSpire 7u10txg, a premium Wi‑Fi 7 gateway with an integrated XGS‑PON fiber terminal. Large US broadband providers including Cox Communications, Brightspeed, ALLO, CityFibre and Conexon use the device.
CERT/CC coordinated public disclosure on June 7 after Quintana’s attempts to notify Calix went unanswered. Calix has not responded to requests for comment.
With no patch available, Quintana advises users to disable UPnP through the device’s administrative interface. CERT/CC notes that in some cases the setting may be locked, requiring affected customers to contact their ISP to request deactivation. The workaround disables automatic port opening, which may affect some gaming applications, but administrators can still open ports manually.
For Malaysian businesses, the risk is limited because Calix routers are primarily deployed in the US broadband market rather than in Malaysia.