Unpatched Calix flaw lets hackers bypass NAT to expose internal devices
An unpatched vulnerability in Calix GS7 XGS residential routers allows remote attackers to create port-forwarding rules, exposing local network devices to the public internet. The flaw affects devices running EXOS/6.6.47 firmware and has no fix yet.
Intelligence analysis by Llama

A security researcher discovered a missing authentication issue in Calix routers, allowing hackers to bypass NAT and expose internal devices. The flaw affects multiple US broadband providers and has no fix yet.
Imagine you have a router that helps keep your home network safe by hiding it from the public internet. But, if someone finds a way to trick the router into revealing your home network's address, they can access all the devices connected to it. This is what's happening with the Calix flaw, where hackers can bypass the router's safety features and expose internal devices to the public internet.
Analysis
Calix Router Vulnerability Overview
The unpatched Calix flaw, tracked as CVE-2026-75501, affects Calix GS7 XGS residential routers used by multiple US broadband providers. The vulnerability allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. The flaw is caused by the device exposing the MiniUPnPd control endpoint on the WAN interface on TCP port 5000 without access controls.
Impact of the Vulnerability
The CVE-2026-75501 vulnerability is significant because it allows hackers to bypass the router's Network Address Translation (NAT) and firewall protections. This means that attackers can expose internal cameras, network-attached storage (NAS) devices, administrative interfaces, and IoT appliances to the public internet. The vulnerability is particularly concerning because it can be exploited by sending a single unauthenticated SOAP request from anywhere in the world.
Workaround and Recommendations
Security researcher Brian Khan Quintana recommends that users of the vulnerable device disable UPnP through the administrative interface. This workaround disables automatic port opening, which some games rely on, but it's always possible to open specific ports manually. CERT/CC also notes that the setting might be locked in some cases, and users who can't change it should contact their ISP to request the deactivation.
Implications and Future Directions
The discovery of the Calix flaw highlights the importance of regular security updates and patches for critical infrastructure devices. The lack of a fix for the CVE-2026-75501 vulnerability underscores the need for vendors to prioritize security and provide timely patches for identified vulnerabilities. In the meantime, users of the affected devices should take steps to mitigate the risk, such as disabling UPnP and ensuring that their devices are running the latest firmware.
Key points
- An unpatched vulnerability in Calix GS7 XGS residential routers allows remote attackers to create port-forwarding rules, exposing local network devices to the public internet.
- The flaw affects devices running EXOS/6.6.47 firmware and has no fix yet.
- Security researcher Brian Khan Quintana recommends disabling UPnP through the administrative interface as a workaround.
- CERT/CC notes that the setting might be locked in some cases, and users who can't change it should contact their ISP to request the deactivation.
If the affected devices are patched or users take steps to mitigate the risk, the impact of the Calix flaw can be minimized. Additionally, the discovery of the vulnerability highlights the importance of prioritizing security and providing timely patches for critical infrastructure devices.
The lack of a fix for the CVE-2026-75501 vulnerability and the potential for widespread exploitation of the flaw are significant concerns. If left unaddressed, the Calix flaw could lead to widespread exposure of internal devices and potentially catastrophic consequences.



