Critical Calix Router Flaw Exposes Home Networks to Remote Attacks

Critical Calix Router Flaw Exposes Home Networks to Remote Attacks

First seen 25 Aug 2026, 17:21 UTC BleepingcomputerTechtimeswww.bleepingcomputer.com 67.5

Article Content

Browse articles
ThreatCluster

A severe vulnerability in the Calix GS5239XG router, tracked as CVE-2026-75501, allows remote attackers to create port-forwarding rules without authentication, exposing internal devices to the internet. Discovered by researcher Brian Khan Quintana, the flaw affects devices running EXOS/6.6.47 firmware. Despite multiple attempts to notify Calix, no patch or public statement has been issued. The vulnerability arises from the router's UPnP service being accessible on the public WAN interface, enabling unauthenticated SOAP requests. This can lead to unauthorized access to internal cameras, NAS devices, and IoT appliances. Users are advised to disable UPnP as a temporary measure, but many may not have the option due to ISP restrictions. The issue affects numerous broadband customers across the U.S. who use the GigaSpire 7u10txg model.

Key Points: • CVE-2026-75501 allows remote unauthenticated access to internal network devices. • Calix has not issued a patch or public statement regarding the vulnerability. • Users are advised to disable UPnP to mitigate risks, but this may not be possible for all.

Timeline

2015-05-01
CVE-2014-8361 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-09-09
CVE-2025-7635 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-09-09
CVE-2025-53914 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-21
CVE-2026-75501 published
The vulnerability in Calix routers was disclosed by Carnegie Mellon CERT after researcher Quintana's findings.
Techtimes
2026-08-24
Public disclosure coordinated by CERT/CC
After unsuccessful attempts to contact Calix, CERT/CC published the vulnerability details, highlighting its severity.
Bleepingcomputer
Recent
No patch or fix available
Calix has not provided any updates or fixes for the vulnerability, leaving users at risk.
Techtimes