Back Scworld Unpatched Calix router vulnerability allows remote attackers to expose home networks
As reported by Bleeping Computer, a critical vulnerability in Calix GS7 XGS residential routers, utilized by numerous U.S. broadband providers, enables unauthenticated remote attackers to establish port-forwarding rules, thereby exposing local network devices to the public internet.
The flaw, identified as CVE-2026-75501, affects devices running EXOS/6.6.47 firmware. Security researcher Brian Khan Quintana discovered that the router exposes its UPnP control endpoint on the WAN interface without proper access controls. This allows attackers to send unauthenticated SOAP requests to add, delete, or enumerate port mappings, effectively bypassing the router's NAT and firewall protections. This could expose internal devices like cameras, NAS drives, and IoT appliances to the internet.
Quintana demonstrated that a single request could create a permanent firewall hole that survives reboots. Calix, a major vendor for U.S. broadband providers like Cox Communications and Brightspeed, has not yet released a patch. Quintana recommends disabling UPnP as a workaround, though this may affect some gaming functionality. Users unable to disable UPnP should their ISP.
Source: Bleeping Computer
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
