As reported by Bleeping Computer, a critical vulnerability in Calix GS7 XGS residential routers, utilized by numerous U.S. broadband providers, enables unauthenticated remote attackers to establish port-forwarding rules, thereby exposing local network devices to the public internet.The flaw, identified as CVE-2026-75501, affects devices running EXOS/6.6.47 firmware. Security researcher Brian Khan Quintana discovered that the router exposes its UPnP control endpoint on the WAN interface without proper access controls. This allows attackers to send unauthenticated SOAP requests to add, delete, or enumerate port mappings, effectively bypassing the router's NAT and firewall protections. This could expose internal devices like cameras, NAS drives, and IoT appliances to the internet.Quintana demonstrated that a single request could create a permanent firewall hole that survives reboots. Calix, a major vendor for U.S. broadband providers like Cox Communications and Brightspeed, has not yet released a patch. Quintana recommends disabling UPnP as a workaround, though this may affect some gaming functionality. Users unable to disable UPnP should contact their ISP.Source: Bleeping Computer
Network Security
Unpatched Calix router vulnerability allows remote attackers to expose home networks
(Adobe Stock)
An In-Depth Guide to Network Security
Get essential knowledge and practical strategies to fortify your network security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
