Calix router vulnerability enables unauthenticated remote port mapping
A critical authentication flaw in Calix GS7 XGS routers allows remote attackers to create port-forwarding rules without credentials, exposing internal devices to the internet. The vulnerability, tracked as CVE-2026-75501, stems from an unprotected UPnP endpoint on the WAN interface. The researcher reported it to CERT/CC after the vendor failed to respond, and it affects multiple US broadband providers.
Expanded Detail
EXPANDED:
The GS5239XG, also sold
Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Related stories
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Unpatched Calix flaw lets hackers bypass NAT to expose internal devices.” Browse more stories.