PatchSiren cyber security CVE debrief
CVE-2026-75501 Calix CVE debrief
The Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router has a vulnerability that allows unauthenticated remote attackers to modify NAT port-forwarding rules via the UPnP WANIPConnection service. This issue arises from the device exposing the MiniUPnPd control endpoint on the WAN interface on TCP port 5000 without access controls. A remote attacker can send crafted SOAP requests to add, delete, or enumerate port mappings, or to query the external IP address, without authentication. Successful exploitation may enable bypass of the firewall/NAT boundary and exposure of internal LAN services to the public internet. Administrators and users should be aware of this vulnerability and take necessary actions to prevent potential exposure of internal LAN services. The CVE record was published on 2026-08-21T15:16:47.070Z and has not been modified since then.
- Vendor
- Calix
- Product
- GS7 XGS (GS5239XG)
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-08-21
Who should care
Administrators and users of the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router should be aware of this vulnerability and take necessary actions to prevent potential exposure of internal LAN services. This includes reviewing and updating configurations, ensuring that appropriate mitigations are in place, and monitoring for suspicious activity. IT and security teams responsible for managing network infrastructure and ensuring the security of residential networks should prioritize patching and verifying the integrity of their systems.
Technical summary
The Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router has a vulnerability that allows unauthenticated remote attackers to modify NAT port-forwarding rules via the UPnP WANIPConnection service. The device exposes the MiniUPnPd control endpoint on the WAN interface on TCP port 5000 without access controls. A remote attacker can send crafted SOAP requests to add, delete, or enumerate port mappings, or to query the external IP address, without authentication. Successful exploitation may enable bypass of the firewall/NAT boundary and exposure of internal LAN services to the public internet. The vulnerability impacts the router's ability to maintain secure network configurations.
Defensive priority
Administrators should prioritize patching the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router to prevent potential exposure of internal LAN services.
Recommended defensive actions
- Patch the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router
- Disable UPnP WANIPConnection service on the WAN interface
- Restrict access to TCP port 5000
- Monitor for suspicious activity on the WAN interface
- Verify and update firewall/NAT configurations
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE description indicates a vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router, allowing unauthenticated remote attackers to modify NAT port-forwarding rules via the UPnP WANIPConnection service. The device exposes the MiniUPnPd control endpoint on the WAN interface on TCP port 5000 without access controls.
Official resources
-
CVE-2026-75501 CVE record
CVE.org
-
CVE-2026-75501 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
- Source reference
-
Source reference
af854a3a-2127-422b-91ae-364da2661108
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T15:16:47.070Z and has not been modified since then.