Calix router vulnerability enables unauthenticated remote port mapping
A critical authentication flaw in Calix GS7 XGS routers allows remote attackers to create port-forwarding rules without credentials, exposing internal devices to the internet. The vulnerability, tracked as CVE-2026-75501, stems from an unprotected UPnP endpoint on the WAN interface. The researcher reported it to CERT/CC after the vendor failed to respond, and it affects multiple US broadband providers.
Related stories
Over 270 Zimbra servers compromised in ongoing RCE attacks · Cybersecurity
This summary is AI-generated and original to Mobble; the linked article is the authoritative source.
Original headline: “Unpatched Calix flaw lets hackers bypass NAT to expose internal devices.” Browse more stories.