
Unpatched Calix router flaw exposes home devices
An unpatched security vulnerability in Calix residential routers can allow remote, unauthenticated attackers to expose devices on a home network to the public internet. Tracked as CVE-2026-75501, the issue affects Calix GS7 XGS routers, model GS5239XG, running EXOS/6.6.47 firmware. The model is also marketed as the GigaSpire 7u10txg, a gateway that combines Wi-Fi 7 capabilities with an integrated XGS-PON fiber terminal. Calix works with major US broadband providers including Cox Communications, Brightspeed, ALLO, CityFibre and Conexon. Security researcher Brian Khan Quintana discovered the flaw. It stems from missing authentication on the router’s Wide Area Network, or WAN, interface. The device exposes the MiniUPnPd control endpoint on TCP port 5000 without access controls. According to the Carnegie Mellon CERT Coordination Center, known as CERT/CC, affected firmware binds the router’s UPnP WANIPConnection SOAP service to the public WAN interface. That exposure lets an attacker on the public internet send unauthenticated SOAP requests to add, delete or enumerate port mappings, or query the external IP address. An attacker can therefore bypass the router’s Network Address Translation, or NAT, and firewall protections, directing traffic from a public port to a chosen device on the local network. The devices that may be exposed include home security cameras, network-attached storage drives, administrative interfaces and Internet of Things appliances. Quintana said the attack requires no action from the router owner. “One unauthenticated request from anywhere in the world is enough to open a permanent hole through the router’s firewall to any device inside the house,” he said. He added that the attack needs no password, creates no prompt or on-screen notice, and leaves a rule that survives a reboot. In testing, a port mapping created without an expiration remained active after the router was power-cycled. Quintana tried to notify Calix on June 7 but did not receive a response, then reported the issue to CERT/CC. After multiple attempts to contact the vendor also received no response, CERT/CC coordinated a public disclosure and Quintana published the technical details. BleepingComputer contacted Calix about the flaw, the affected device models and whether a patch would be released, but had not received a response when the report was published. No fix for CVE-2026-75501 was available in the supplied report. Quintana recommends disabling UPnP through the router administration interface: Advanced, Security, then UPnP. Turning it off prevents automatic port opening, which some games use, though users can manually open specific ports when needed. CERT/CC notes that providers may lock this setting; customers unable to change it should ask their internet provider to disable UPnP. Somali diaspora households in the United States using a GigaSpire 7u10txg or GS5239XG should check the router’s settings, particularly where home cameras or storage devices are connected. If the setting is unavailable, contacting the internet provider is the practical next step.
Read our sourcing and corrections policy
This article was prepared by our automated editorial system, which summarized and translated the source above. No human editor reviewed this article individually before publication.



Be the first to comment on this story!