A critical vulnerability (CVE-2026-75501) has been identified in the Calix GS7 XGS GS5239XG router, related to missing authentication in its UPnP service. This flaw allows remote attackers to access the router's critical functions without authentication, potentially exposing internal devices to the internet. The affected firmware version is EXOS/6.6.47, and while details of the vulnerability and proof-of-concept exploit code are publicly available, there have been no confirmed exploitations in the wild. Users are advised to disable the UPnP service and filter inbound traffic to TCP port 5000 as a precaution.
Router flaw lets attackers bypass authentication via UPnP
CyberSIXT Evidence Panel
Article by CyberSIXT