Techtimes
Critical Calix Router Flaw Exposes Home Networks to Attack
Article Content
A critical vulnerability in Calix GS5239XG routers, tracked as CVE-2026-75501, allows unauthenticated remote attackers to create port-forwarding rules, exposing internal devices to the internet. Discovered by researcher Brian Khan Quintana, the flaw stems from the router's UPnP control endpoint being accessible on the WAN interface without authentication. This issue affects devices running EXOS/6.6.47 firmware and has been confirmed by the Carnegie Mellon CERT Coordination Center. No patch or firmware update has been released by Calix, and users are advised to disable UPnP as a temporary workaround. The vulnerability places millions of devices at risk, as many routers are provisioned with UPnP enabled by default. The potential impact includes exposure of sensitive internal devices like cameras and NAS drives. The situation is urgent, with active exploitation observed in the wild, as attackers can easily manipulate the router settings without user intervention.
Key Points: • CVE-2026-75501 allows remote attackers to bypass NAT and firewall protections. • No patch is available, and users are advised to disable UPnP as a workaround. • The vulnerability affects Calix GS5239XG routers, widely used by U.S. broadband providers.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.