Published · 15h agoSecurity2 min read
Calix fiber gateway takes port-forward orders from anyone, and the vendor has not answered
CVE-2026-75501 puts an unauthenticated UPnP control endpoint on the WAN side of a premium ISP gateway. With no patch and no vendor reply, the carriers own the mitigation.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- CVE-2026-75501, a missing-authentication bug in Calix GS7 XGS (GS5239XG) routers, lets remote unauthenticated attackers create port-forwarding rules. There is no patch.
- Calix supplies US broadband providers including Cox Communications, Brightspeed, ALLO, CityFibre and Conexon.
- Researcher Brian Khan Quintana tried the vendor on June 7, got nowhere, and took the report to Carnegie Mellon's CERT Coordination Center, which coordinated disclosure.
- In testing from outside his own network, a mapping created with no expiration was still active after the router was power-cycled.
- The recommended step is turning off UPnP in the gateway's admin interface, since no fix exists.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposureCameras, NAS boxes, admin panels and IoT gear behind these gateways become addressable from the public internet without anyone touching the subscriber's credentials.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
An unpatched vulnerability tracked as CVE-2026-75501, a missing authentication issue in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers, allows remote unauthenticated attackers to create port-forwarding rules that expose local network devices to the public internet.
ReportedView cited source - [3]
CERT/CC states the device exposes the MiniUPnPd control endpoint on the WAN interface on TCP port 5000 without access controls, binding its UPnP WANIPConnection SOAP service to the public WAN interface.
- [4]
An attacker on the public internet can send unauthenticated SOAP requests to add, delete, or enumerate port mappings, or to query the external IP address.
ReportedView cited source - [5]
Security researcher Brian Khan Quintana discovered the flaw, tried to notify the vendor on June 7 without success, and reported it to the Carnegie Mellon CERT Coordination Center.
ReportedView cited source - [6]
After multiple attempts to contact the vendor produced no response, CERT/CC coordinated a public disclosure and Quintana published the technical details.
ReportedView cited source
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- bleepingcomputer.comBill ToulasyesterdayUnpatched Calix flaw lets hackers bypass NAT to expose internal devices
- scworld.comSC Staff12h agoUnpatched Calix router vulnerability allows remote attackers to expose home networks
Additional citations
- CERT/CC, via BleepingComputer
- Brian Khan Quintana, via BleepingComputer


