Skip to main content
EPSS 0.6%top 53%

VU#756733: Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability

0
Low
VulnerabilityCVE-2026-75501iotremotecvecve-2026-75501cwe-306
Published: 08/21/2026 (08/21/2026, 14:47:04 UTC)
Source: CERT/CC

Description

The Calix GS7 XGS GS5239XG residential router was initially reported to have a missing authentication vulnerability in its UPnP WANIPConnection service exposed on the WAN interface at TCP port 5000. This could have allowed unauthenticated remote attackers to modify NAT port-forwarding rules, potentially exposing internal LAN devices. However, after thorough investigation and testing by Calix and CERT/CC, it was determined that the default firmware configuration blocks inbound WAN traffic to TCP port 5000, preventing exploitation. No affected customer deployments or required mitigations have been identified. The vulnerability report has been retracted as the issue could not be reproduced under normal conditions.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/17/2026, 22:18:01 UTC

Technical Analysis

The reported vulnerability CVE-2026-75501 concerned a missing authentication issue in the UPnP WANIPConnection SOAP service on Calix GS7 XGS GS5239XG routers running EXOS firmware, which binds to TCP port 5000 on the WAN interface. This would have allowed unauthenticated remote attackers to add, delete, or enumerate NAT port mappings, potentially bypassing firewall and NAT protections. However, Calix's investigation found that the default WAN firewall blocks inbound traffic to TCP port 5000, preventing access to the UPnP service from outside the network. Multiple tests across devices, firmware versions, and environments confirmed that the vulnerability could not be reproduced and that security controls function as designed. Calix has not identified any customer-impacting exposure or affected deployments and states no action is required.

Potential Impact

If exploitable, the vulnerability would have allowed unauthenticated remote attackers to manipulate NAT port-forwarding rules, bypassing firewall and NAT protections to expose internal LAN devices to the public internet. This could have posed significant risks to residential users with network-connected devices. However, due to default firewall rules blocking access to the vulnerable service, no actual exposure has been confirmed in deployed systems. No customer-impacting incidents or exposures have been identified.

Mitigation Recommendations

No mitigation or patch is currently required as Calix has confirmed that the default firmware configuration blocks inbound WAN traffic to TCP port 5000, preventing exploitation. Users do not need to take any action at this time. If users have concerns, they may consider disabling UPnP or filtering inbound traffic to TCP port 5000, but these are not mandated by Calix. The vendor continues to monitor the situation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.82,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://kb.cert.org/vuls/id/756733","fetched":true,"fetchedAt":"2026-08-21T14:50:59.369Z","wordCount":529}

Threat ID: 6a8865d3acd9273b49484feb

Added to database: 08/21/2026, 14:50:59 UTC

Last enriched: 09/17/2026, 22:18:01 UTC

Last updated: 10/04/2026, 18:55:08 UTC

Views: 102

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses