CVE-2026-75501
Calix · GS7 XGS (GS5239XG)
A flaw in Calix EXOS firmware allows unauthenticated remote attackers to modify NAT port forwarding rules via the UPnP WANIPConnection service on the device WAN interface.
Executive summary
A critical vulnerability in the Calix GS7 XGS residential router allows unauthenticated attackers to bypass firewall protections and expose internal services to the public internet.
Vulnerability
This is a missing authentication for critical function flaw (CWE-306) where the MiniUPnPd control endpoint is exposed on the WAN interface without access controls. An unauthenticated attacker can send crafted SOAP requests to manipulate NAT port mappings or enumerate internal network configurations.
Business impact
The ability for an unauthenticated attacker to modify NAT rules poses a significant security risk by allowing unauthorized exposure of internal LAN services to the public internet. With a CVSS score of 7.5, this high-severity vulnerability could lead to the compromise of internal systems that were previously shielded by the router firewall. Such exposure significantly increases the attack surface for internal devices and risks data theft or unauthorized system control.
Remediation
Immediate Action: As no patch is currently confirmed, administrators should disable the UPnP service on the WAN interface immediately if the functionality is not strictly required.
Proactive Monitoring: Security teams should monitor firewall logs for suspicious inbound traffic on TCP port 5000 and unusual NAT mapping modifications.
Compensating Controls: Deploy a network-level access control list or firewall rule to block all inbound traffic to TCP port 5000 from the WAN interface.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the referenced security research.
Analyst recommendation
This vulnerability presents a clear and present danger to network integrity by allowing attackers to bypass perimeter security. Given the existence of a public proof-of-concept, users must take immediate action to restrict access to the affected UPnP service. We strongly recommend disabling this service on the WAN interface until an official firmware update is released and verified by the vendor.