
A newly disclosed vulnerability affecting the Calix GS7 XGS residential router can reportedly allow an unauthenticated attacker on the internet to create port-forwarding rules and expose devices inside a home or small-business network. The issue is tracked as CVE-2026-75501 and affects the GS5239XG model, also marketed as the GigaSpire 7u10txg, running EXOS/6.6.47 firmware.
The weakness involves a Universal Plug and Play service exposed on the router's public-facing network interface. According to the disclosure coordinated through Carnegie Mellon University's CERT Coordination Center, the service accepts requests without the access controls that should prevent outsiders from changing network mappings.
What an attacker could do
Port forwarding instructs a router to send incoming internet traffic to a particular device on the private network. It is useful when intentionally configured, but a malicious mapping could make cameras, storage appliances, administrative interfaces or other connected devices reachable from the public internet.
Reported capabilities include adding arbitrary mappings, removing existing ones, listing current mappings and retrieving the router's public IP address. A researcher testing the flaw said a mapping with no expiration remained in place after the router was restarted, increasing the potential persistence of an unwanted change.
The vulnerability does not automatically compromise every device behind the router. It removes an important protective boundary and gives an attacker an opportunity to reach services that were never meant to be internet-facing. The final impact would depend on the security of each exposed device, including its passwords, software version and configuration.
What affected users can do
No vendor patch was available when the issue was publicly reported. The current mitigation is to disable UPnP in the router's administration interface. That can affect games or applications that rely on automatic port creation, but necessary mappings can be configured manually.
Some internet providers lock parts of the router configuration. Customers who cannot change the UPnP setting should contact their provider and ask whether they use the affected model and firmware, whether the vulnerable service is reachable from the public internet and whether UPnP can be disabled remotely.
Users should avoid exposing router administration pages, cameras and network storage directly to the internet. Strong unique passwords and current firmware remain important, but they do not replace a fix for the missing authentication reported in CVE-2026-75501.
See an error? Read our corrections policy or email [email protected].
TECHNOMALIST

