Techtimes
Critical Calix Router Flaw Exposes Home Networks to Remote Attacks
Article Content
A severe vulnerability in the Calix GS5239XG router, tracked as CVE-2026-75501, allows remote attackers to create port-forwarding rules without authentication, exposing internal devices to the internet. Discovered by researcher Brian Khan Quintana, the flaw affects devices running EXOS/6.6.47 firmware. Despite multiple attempts to notify Calix, no patch or public statement has been issued. The vulnerability arises from the router's UPnP service being accessible on the public WAN interface, enabling unauthenticated SOAP requests. This can lead to unauthorized access to internal cameras, NAS devices, and IoT appliances. Users are advised to disable UPnP as a temporary measure, but many may not have the option due to ISP restrictions. The issue affects numerous broadband customers across the U.S. who use the GigaSpire 7u10txg model.
Key Points: • CVE-2026-75501 allows remote unauthenticated access to internal network devices. • Calix has not issued a patch or public statement regarding the vulnerability. • Users are advised to disable UPnP to mitigate risks, but this may not be possible for all.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.