Review
Calix
CVE published 2026-08-21
CVE-2026-75501
The Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router has a vulnerability that allows unauthenticated remote attackers to modify NAT port-forwarding rules via the UPnP WANIPConnection service. This issue arises from the device exposing the MiniUPnPd control endpoint on the WAN interface on TCP port 5000 without access controls. A remote attacker can send crafted SOAP requests to add, delet [truncated]