Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

VU#756733: Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability

0
High
VulnerabilityCVE-2026-75501iotremotecvecve-2026-75501cwe-306
Published: 08/21/2026 (08/21/2026, 14:47:04 UTC)
Source: CERT/CC

Description

A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router allows unauthenticated remote attackers to modify NAT port‑forwarding rules via the UPnP WANIPConnection service. The device exposes the MiniUPnPd control endpoint on the WAN interface on TCP port 5000 without access controls. A remote attacker can send crafted SOAP requests to add, delete, or enumerate port mappings, or to query the external IP address, without authentication. Successful exploitation may enable bypass of the firewall/NAT boundary and exposure of internal LAN services to the public internet.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/21/2026, 14:51:15 UTC

Technical Analysis

The Calix GS7 XGS GS5239XG router includes a UPnP service implemented via MiniUPnPd 2.3.7 that is exposed on the WAN interface without requiring authentication. Specifically, the WANIPConnection SOAP service listens on TCP port 5000 and accepts unauthenticated SOAP requests. This allows remote attackers to add, delete, and enumerate NAT port mappings, effectively bypassing NAT and firewall protections. The vulnerability is identified as CVE-2026-75501. The CERT/CC was unable to coordinate disclosure with Calix, and no official patch or vendor statement is available. Users are advised to disable UPnP or filter inbound TCP port 5000 traffic to mitigate exposure.

Potential Impact

An unauthenticated remote attacker can remotely query and manipulate NAT port mappings on the affected router. By creating arbitrary port-forwarding rules, the attacker can bypass NAT and firewall protections, exposing internal LAN devices such as security cameras, NAS, and IoT appliances to the public internet. This poses a significant risk to residential users relying on the default UPnP-enabled configuration.

Mitigation Recommendations

No vendor patch or official fix is currently available. Users should disable UPnP on the router's administrative interface to reduce exposure. If this setting is unavailable or locked, contacting the ISP to disable UPnP at the carrier level is recommended. Alternatively, filtering inbound traffic to TCP port 5000 via the router, a secondary firewall, or the ISP can prevent external access to the WANIPConnection service.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.82,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://kb.cert.org/vuls/id/756733","fetched":true,"fetchedAt":"2026-08-21T14:50:59.369Z","wordCount":529}

Threat ID: 6a8865d3acd9273b49484feb

Added to database: 08/21/2026, 14:50:59 UTC

Last enriched: 08/21/2026, 14:51:15 UTC

Last updated: 08/21/2026, 15:27:13 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses