PT-2026-79389 · Calix · Exos

CVE-2026-75501

·

Published

2026-08-21

·

Updated

2026-08-25

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Calix EXOS firmware version 6.6.47
Description An issue in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router allows unauthenticated remote attackers to modify NAT port-forwarding rules. The device exposes the MiniUPnPd control endpoint on the WAN interface via TCP port 5000 without access controls. By sending crafted SOAP requests to the UPnP WANIPConnection service, an attacker can add, delete, or enumerate port mappings and query the external IP address. This can lead to a bypass of the firewall/NAT boundary, exposing internal LAN services to the public internet.
Recommendations For version 6.6.47, disable UPnP entirely in the router admin panel. Block inbound TCP port 5000 at the ISP or edge level. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75501

Affected Products

Exos