PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75501 Calix CVE debrief

The Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router has a vulnerability that allows unauthenticated remote attackers to modify NAT port-forwarding rules via the UPnP WANIPConnection service. This issue arises from the device exposing the MiniUPnPd control endpoint on the WAN interface on TCP port 5000 without access controls. A remote attacker can send crafted SOAP requests to add, delete, or enumerate port mappings, or to query the external IP address, without authentication. Successful exploitation may enable bypass of the firewall/NAT boundary and exposure of internal LAN services to the public internet. Administrators and users should be aware of this vulnerability and take necessary actions to prevent potential exposure of internal LAN services. The CVE record was published on 2026-08-21T15:16:47.070Z and has not been modified since then.

Vendor
Calix
Product
GS7 XGS (GS5239XG)
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-08-21
Advisory published
2026-08-21
Advisory updated
2026-08-21

Who should care

Administrators and users of the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router should be aware of this vulnerability and take necessary actions to prevent potential exposure of internal LAN services. This includes reviewing and updating configurations, ensuring that appropriate mitigations are in place, and monitoring for suspicious activity. IT and security teams responsible for managing network infrastructure and ensuring the security of residential networks should prioritize patching and verifying the integrity of their systems.

Technical summary

The Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router has a vulnerability that allows unauthenticated remote attackers to modify NAT port-forwarding rules via the UPnP WANIPConnection service. The device exposes the MiniUPnPd control endpoint on the WAN interface on TCP port 5000 without access controls. A remote attacker can send crafted SOAP requests to add, delete, or enumerate port mappings, or to query the external IP address, without authentication. Successful exploitation may enable bypass of the firewall/NAT boundary and exposure of internal LAN services to the public internet. The vulnerability impacts the router's ability to maintain secure network configurations.

Defensive priority

Administrators should prioritize patching the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router to prevent potential exposure of internal LAN services.

Recommended defensive actions

  • Patch the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router
  • Disable UPnP WANIPConnection service on the WAN interface
  • Restrict access to TCP port 5000
  • Monitor for suspicious activity on the WAN interface
  • Verify and update firewall/NAT configurations
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE description indicates a vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router, allowing unauthenticated remote attackers to modify NAT port-forwarding rules via the UPnP WANIPConnection service. The device exposes the MiniUPnPd control endpoint on the WAN interface on TCP port 5000 without access controls.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T15:16:47.070Z and has not been modified since then.