Critical Calix Router Flaw Exposes Home Networks to Attack

Critical Calix Router Flaw Exposes Home Networks to Attack

First seen 25 Aug 2026, 17:21 UTC BleepingcomputerTechtimesScworldwww.bleepingcomputer.com 69.9

Article Content

Browse articles
ThreatCluster

A critical vulnerability in Calix GS5239XG routers, tracked as CVE-2026-75501, allows unauthenticated remote attackers to create port-forwarding rules, exposing internal devices to the internet. Discovered by researcher Brian Khan Quintana, the flaw stems from the router's UPnP control endpoint being accessible on the WAN interface without authentication. This issue affects devices running EXOS/6.6.47 firmware and has been confirmed by the Carnegie Mellon CERT Coordination Center. No patch or firmware update has been released by Calix, and users are advised to disable UPnP as a temporary workaround. The vulnerability places millions of devices at risk, as many routers are provisioned with UPnP enabled by default. The potential impact includes exposure of sensitive internal devices like cameras and NAS drives. The situation is urgent, with active exploitation observed in the wild, as attackers can easily manipulate the router settings without user intervention.

Key Points: • CVE-2026-75501 allows remote attackers to bypass NAT and firewall protections. • No patch is available, and users are advised to disable UPnP as a workaround. • The vulnerability affects Calix GS5239XG routers, widely used by U.S. broadband providers.

Timeline

2015-05-01
CVE-2014-8361 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2017-03-17
CVE-2017-0144 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2017-05-25
Public exploit for CVE-2017-7494 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2025-09-09
CVE-2025-53914 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-09-09
CVE-2025-7635 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-21
CVE-2026-75501 published
The flaw in Calix routers was disclosed by Carnegie Mellon CERT after multiple failed notifications to the vendor.
Techtimes
2026-08-24
Public disclosure of vulnerability details
Brian Khan Quintana published technical details of the vulnerability after CERT/CC coordinated the disclosure.
Bleepingcomputer
2026-08-25
Multiple outlets report on vulnerability
BleepingComputer and other outlets highlight the critical nature of the vulnerability and the lack of a patch.
Bleepingcomputer
2026-08-25
Calix vulnerability linked to EternalSilence attacks
The vulnerability is exploited in a campaign dubbed 'Eternal Silence', affecting thousands of routers.
Bleepingcomputer