An unpatched flaw in a Calix residential fiber router can let anyone on the internet punch holes through a home network and expose internal devices. The issue, CVE-2026-75501, affects Calix GS7 XGS model GS5239XG (also sold as GigaSpire 7u10txg) running EXOS/6.6.47 firmware. CERT/CC says the router exposes its MiniUPnPd WANIPConnection control service on the public WAN interface on TCP port 5000 without authentication, allowing unauthenticated SOAP requests to add, delete, or list port-forwarding rules.
Why it matters: Affected households and small-office users could have cameras, storage devices, admin panels, or other internet-reachable equipment exposed without warning, and there is no vendor patch yet. Users should disable Universal Plug and Play (UPnP) if possible or ask their broadband provider to do so, especially if the device was ISP-supplied.
Bill Toulas
2026.08.24
100% relevant
This article appears to be the initial public disclosure of CVE-2026-75501, including affected product details, the missing-authentication root cause, and interim mitigations while no patch is available.
← Back to all stories