Calix Flaws

Overview

A critical vulnerability in Calix GS7 XGS (GS5239XG) residential routers, widely deployed by U.S. broadband providers, allows attackers to bypass NAT and firewall protections to expose internal devices directly to the internet. Tracked as CVE‑2026‑75501, the flaw remains unpatched, raising serious concerns for households and ISPs alike.

Vulnerability Details

  • CVE‑2026‑75501: Missing authentication issue in EXOS/6.6.47 firmware.
  • Root cause: The router exposes the MiniUPnPd control endpoint on the WAN interface (TCP port 5000) without access controls.
  • Impact: Attackers can send unauthenticated SOAP requests to:
    • Create port‑forwarding rules
    • Delete existing mappings
    • Enumerate current mappings
    • Retrieve external IP address

This effectively allows hackers to open permanent holes in the router’s firewall, exposing cameras, NAS devices, IoT appliances, and admin interfaces.

Discovery & Disclosure

  • Discovered by Brian Khan Quintana on June 7, 2026.
  • Vendor Calix did not respond to multiple disclosure attempts.
  • Coordinated public disclosure handled by CERT/CC.
  • Proof‑of‑concept requests show that port mappings survive reboots, making exploitation persistent.

Why It’s Dangerous

  • No authentication required: One request from anywhere in the world can expose internal devices.
  • Persistent exposure: Port‑forwarding rules remain active even after reboot.
  • Broad provider impact: Calix routers are used by Cox Communications, Brightspeed, ALLO, CityFibre, Conexon, and others.
  • Premium device risk: The GS5239XG (also marketed as GigaSpire 7u10txg) is a flagship Wi‑Fi 7 gateway with integrated fiber terminal, making it attractive to high‑end deployments.

Workarounds

Until a patch is released, users should:

  • Disable UPnP via the admin interface (Advanced → Security → UPnP).
  • Manually configure ports for applications like games that rely on automatic port opening.
  • Contact ISP if the UPnP setting is locked.
  • Monitor exposed devices for unusual traffic or unauthorized access attempts.

Expert in the Cloud Insight

This flaw is a stark reminder that consumer routers are high‑value targets. By exposing UPnP controls on the WAN interface, Calix inadvertently gave attackers a way to turn home networks inside‑out. The lesson is clear: default configurations must prioritize security over convenience, and ISPs should proactively disable risky features until patches are available.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.