VU#756733: Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability
A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router allows unauthenticated remote attackers to modify NAT port‑forwarding rules via the UPnP WANIPConnection service. The device exposes the MiniUPnPd control endpoint on the WAN interface on TCP port 5000 without access controls. A remote attacker can send crafted SOAP requests to add, delete, or enumerate port mappings, or to query the external IP address, without authentication. Successful exploitation may enable bypass of the firewall/NAT boundary and exposure of internal LAN services to the public internet.
AI Analysis
Technical Summary
The Calix GS7 XGS GS5239XG router includes a UPnP service implemented via MiniUPnPd 2.3.7 that is exposed on the WAN interface without requiring authentication. Specifically, the WANIPConnection SOAP service listens on TCP port 5000 and accepts unauthenticated SOAP requests. This allows remote attackers to add, delete, and enumerate NAT port mappings, effectively bypassing NAT and firewall protections. The vulnerability is identified as CVE-2026-75501. The CERT/CC was unable to coordinate disclosure with Calix, and no official patch or vendor statement is available. Users are advised to disable UPnP or filter inbound TCP port 5000 traffic to mitigate exposure.
Potential Impact
An unauthenticated remote attacker can remotely query and manipulate NAT port mappings on the affected router. By creating arbitrary port-forwarding rules, the attacker can bypass NAT and firewall protections, exposing internal LAN devices such as security cameras, NAS, and IoT appliances to the public internet. This poses a significant risk to residential users relying on the default UPnP-enabled configuration.
Mitigation Recommendations
No vendor patch or official fix is currently available. Users should disable UPnP on the router's administrative interface to reduce exposure. If this setting is unavailable or locked, contacting the ISP to disable UPnP at the carrier level is recommended. Alternatively, filtering inbound traffic to TCP port 5000 via the router, a secondary firewall, or the ISP can prevent external access to the WANIPConnection service.
VU#756733: Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability
Description
A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router allows unauthenticated remote attackers to modify NAT port‑forwarding rules via the UPnP WANIPConnection service. The device exposes the MiniUPnPd control endpoint on the WAN interface on TCP port 5000 without access controls. A remote attacker can send crafted SOAP requests to add, delete, or enumerate port mappings, or to query the external IP address, without authentication. Successful exploitation may enable bypass of the firewall/NAT boundary and exposure of internal LAN services to the public internet.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Calix GS7 XGS GS5239XG router includes a UPnP service implemented via MiniUPnPd 2.3.7 that is exposed on the WAN interface without requiring authentication. Specifically, the WANIPConnection SOAP service listens on TCP port 5000 and accepts unauthenticated SOAP requests. This allows remote attackers to add, delete, and enumerate NAT port mappings, effectively bypassing NAT and firewall protections. The vulnerability is identified as CVE-2026-75501. The CERT/CC was unable to coordinate disclosure with Calix, and no official patch or vendor statement is available. Users are advised to disable UPnP or filter inbound TCP port 5000 traffic to mitigate exposure.
Potential Impact
An unauthenticated remote attacker can remotely query and manipulate NAT port mappings on the affected router. By creating arbitrary port-forwarding rules, the attacker can bypass NAT and firewall protections, exposing internal LAN devices such as security cameras, NAS, and IoT appliances to the public internet. This poses a significant risk to residential users relying on the default UPnP-enabled configuration.
Mitigation Recommendations
No vendor patch or official fix is currently available. Users should disable UPnP on the router's administrative interface to reduce exposure. If this setting is unavailable or locked, contacting the ISP to disable UPnP at the carrier level is recommended. Alternatively, filtering inbound traffic to TCP port 5000 via the router, a secondary firewall, or the ISP can prevent external access to the WANIPConnection service.
Technical Details
- Classification
- {"confidence":0.82,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://kb.cert.org/vuls/id/756733","fetched":true,"fetchedAt":"2026-08-21T14:50:59.369Z","wordCount":529}
Threat ID: 6a8865d3acd9273b49484feb
Added to database: 08/21/2026, 14:50:59 UTC
Last enriched: 08/21/2026, 14:51:15 UTC
Last updated: 08/21/2026, 15:27:13 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.