VU#756733: Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability
Description
The Calix GS7 XGS GS5239XG residential router was initially reported to have a missing authentication vulnerability in its UPnP WANIPConnection service exposed on the WAN interface at TCP port 5000. This could have allowed unauthenticated remote attackers to modify NAT port-forwarding rules, potentially exposing internal LAN devices. However, after thorough investigation and testing by Calix and CERT/CC, it was determined that the default firmware configuration blocks inbound WAN traffic to TCP port 5000, preventing exploitation. No affected customer deployments or required mitigations have been identified. The vulnerability report has been retracted as the issue could not be reproduced under normal conditions.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The reported vulnerability CVE-2026-75501 concerned a missing authentication issue in the UPnP WANIPConnection SOAP service on Calix GS7 XGS GS5239XG routers running EXOS firmware, which binds to TCP port 5000 on the WAN interface. This would have allowed unauthenticated remote attackers to add, delete, or enumerate NAT port mappings, potentially bypassing firewall and NAT protections. However, Calix's investigation found that the default WAN firewall blocks inbound traffic to TCP port 5000, preventing access to the UPnP service from outside the network. Multiple tests across devices, firmware versions, and environments confirmed that the vulnerability could not be reproduced and that security controls function as designed. Calix has not identified any customer-impacting exposure or affected deployments and states no action is required.
Potential Impact
If exploitable, the vulnerability would have allowed unauthenticated remote attackers to manipulate NAT port-forwarding rules, bypassing firewall and NAT protections to expose internal LAN devices to the public internet. This could have posed significant risks to residential users with network-connected devices. However, due to default firewall rules blocking access to the vulnerable service, no actual exposure has been confirmed in deployed systems. No customer-impacting incidents or exposures have been identified.
Mitigation Recommendations
No mitigation or patch is currently required as Calix has confirmed that the default firmware configuration blocks inbound WAN traffic to TCP port 5000, preventing exploitation. Users do not need to take any action at this time. If users have concerns, they may consider disabling UPnP or filtering inbound traffic to TCP port 5000, but these are not mandated by Calix. The vendor continues to monitor the situation.
Technical Details
- Classification
- {"confidence":0.82,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://kb.cert.org/vuls/id/756733","fetched":true,"fetchedAt":"2026-08-21T14:50:59.369Z","wordCount":529}
Threat ID: 6a8865d3acd9273b49484feb
Added to database: 08/21/2026, 14:50:59 UTC
Last enriched: 09/17/2026, 22:18:01 UTC
Last updated: 10/04/2026, 18:55:08 UTC
Views: 102
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.