PT-2026-79389 · Calix · Exos
CVE-2026-75501
·
Published
2026-08-21
·
Updated
2026-08-25
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Calix EXOS firmware version 6.6.47
Description
An issue in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router allows unauthenticated remote attackers to modify NAT port-forwarding rules. The device exposes the MiniUPnPd control endpoint on the WAN interface via TCP port 5000 without access controls. By sending crafted SOAP requests to the UPnP WANIPConnection service, an attacker can add, delete, or enumerate port mappings and query the external IP address. This can lead to a bypass of the firewall/NAT boundary, exposing internal LAN services to the public internet.
Recommendations
For version 6.6.47, disable UPnP entirely in the router admin panel.
Block inbound TCP port 5000 at the ISP or edge level.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exos