Threats Tagged 'cve-2026-75501'
View all threats tagged with 'cve-2026-75501'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-75501'
Click on any threat for detailed analysis and mitigation recommendations
A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router allows unauthenticated remote attackers to modify NAT port-forwarding rules via the UPnP WANIPConnection service. The device exposes the MiniUPnPd control endpoint on the WAN interface on TCP port 5000 without access controls. Attackers can send crafted SOAP requests to add, delete, or enumerate port mappings or query the external IP address without authentication. This may enable bypassing the firewall/NAT boundary and exposing internal LAN services to the public internet. Join the discussion | GCVE Database | 08/21/2026, 15:32:13 UTC Added: 09/16/2026, 03:08:14 UTC |
0 The Calix GS7 XGS GS5239XG residential router was initially reported to have a missing authentication vulnerability in its UPnP WANIPConnection service exposed on the WAN interface at TCP port 5000. This could have allowed unauthenticated remote attackers to modify NAT port-forwarding rules, potentially exposing internal LAN devices. However, after thorough investigation and testing by Calix and CERT/CC, it was determined that the default firmware configuration blocks inbound WAN traffic to TCP port 5000, preventing exploitation. No affected customer deployments or required mitigations have been identified. The vulnerability report has been retracted as the issue could not be reproduced under normal conditions. Join the discussion | CERT/CC | 08/21/2026, 14:47:04 UTC Added: 08/21/2026, 14:50:59 UTC |
Showing 1 to 2 of 2 results