Executive Summary
A critical unpatched vulnerability (CVE-2026-75501) in Calix GS7 XGS residential routers allows remote unauthenticated attackers to bypass NAT and firewall protections by creating arbitrary port-forwarding rules. The flaw affects EXOS/6.6.47 firmware and exposes the MiniUPnPd control endpoint on the WAN interface without authentication, enabling attackers to expose internal devices like cameras, NAS systems, and IoT appliances to the public internet with a single SOAP request. Major U.S. broadband providers including Cox Communications, Brightspeed, and ALLO deploy these vulnerable routers to residential customers.
This vulnerability highlights the growing risk of perimeter-based security failures in an era where remote work and IoT adoption have expanded attack surfaces. With no vendor patch available and limited workarounds, this incident underscores the urgent need for zero-trust network architectures that don't rely solely on NAT and traditional firewall protections.
Why This Matters Now
This unpatched vulnerability in widely-deployed residential routers demonstrates how legacy network security models fail against modern threats, making zero-trust segmentation and continuous monitoring essential for protecting distributed workforces and IoT environments.
Attack Path Analysis
Attackers exploited CVE-2026-75501 in Calix GS7 XGS residential routers to create unauthorized port-forwarding rules via exposed UPnP endpoints, bypassing NAT and firewall protections to expose internal devices. Remote attackers sent unauthenticated SOAP requests to TCP port 5000 on the WAN interface to enumerate and create persistent port mappings. This allowed direct access to internal cameras, NAS devices, IoT appliances, and administrative interfaces from the public internet. Attackers established command and control channels through exposed devices and potentially exfiltrated sensitive data from compromised internal systems. The vulnerability provides a persistent foothold for ongoing surveillance, data theft, or launching further attacks against the compromised network infrastructure.
Kill Chain Progression
Initial Compromise
Description
Attacker discovered exposed UPnP service on TCP port 5000 of vulnerable Calix GS5239XG routers and sent unauthenticated SOAP requests to create port-forwarding rules
Related CVEs
CVE-2026-75501
CVSS 7.5Missing authentication vulnerability in Calix GS7 XGS routers exposes MiniUPnPd control endpoint on WAN interface, allowing remote unauthenticated attackers to create arbitrary port-forwarding rules and bypass NAT protections.
Affected Products:
Calix GS5239XG (GigaSpire 7u10txg) – EXOS/6.6.47
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Remote Services: Cloud Services
Impair Defenses: Disable or Modify Tools
Proxy: Multi-hop Proxy
Network Sniffing
Remote System Discovery
Adversary-in-the-Middle: ARP Cache Poisoning
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Configuration standards for network security controls
Control ID: 1.2.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.02(g)
DORA – ICT Risk Management Framework
Control ID: Article 11
CISA ZTMM 2.0 – Network Environment Security
Control ID: Network Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21.2(a)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Calix router vulnerabilities expose critical ISP infrastructure, enabling attackers to bypass NAT protections and compromise customer network segmentation across broadband providers nationwide.
Internet
Unpatched UPnP flaws allow remote port-forwarding manipulation, exposing internet-connected devices and creating permanent firewall bypasses without authentication or user notification mechanisms.
Utilities
Smart grid and utility IoT devices face exposure through compromised residential gateways, potentially allowing unauthorized access to critical infrastructure monitoring and control systems.
Consumer Electronics
Home automation devices, cameras, and NAS systems become publicly accessible through router exploitation, violating privacy controls and enabling lateral movement attacks.
Sources
- Unpatched Calix flaw lets hackers bypass NAT to expose internal deviceshttps://www.bleepingcomputer.com/news/security/unpatched-calix-flaw-lets-hackers-bypass-nat-to-expose-internal-devices/Verified
- CERT/CC Vulnerability Note VU#756733 - Calix GS7 XGS routers expose UPnP service on WAN interfacehttps://kb.cert.org/vuls/id/756733Verified
- Security Research: CVE-2026-75501 - Calix Router Authentication Bypasshttps://drkq.github.io/security-research/calix-vu756733/Verified
- Calix GigaSpire Wi-Fi 7 Systems Product Pagehttps://www.calix.com/products/platform/unlimited-subscriber/gigaspire/wi-fi-7-systems.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF would be relevant to this UPnP exploitation incident as it could limit the attackers' ability to move laterally between compromised devices and reduce the overall blast radius of the network compromise through segmentation controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The initial UPnP exploitation would likely still succeed, but CNSF visibility controls could detect the unauthorized port mapping creation and anomalous traffic patterns flowing through the newly established forwarding rules.
Control: Zero Trust Segmentation
Mitigation: Zero Trust segmentation policies would likely constrain the attacker's ability to access administrative interfaces by limiting which devices can communicate with privileged services, reducing the scope of privilege escalation opportunities.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely restrict device-to-device communication paths, limiting the attacker's ability to pivot between compromised IoT devices and discover additional network resources beyond the initially exposed systems.
Control: Multicloud Visibility & Control
Mitigation: Visibility controls would likely detect the persistent command and control traffic patterns and unauthorized outbound connections from internal devices, enabling security teams to identify and respond to the ongoing compromise more quickly.
Control: Egress Security & Policy Enforcement
Mitigation: Egress policy enforcement would likely restrict the volume and destinations of outbound data flows from internal devices, limiting the attacker's ability to exfiltrate large amounts of sensitive data to unauthorized external servers.
While some surveillance and privacy violations would likely continue through the exposed port mappings, the overall impact scope would be reduced due to limited lateral access and constrained data exfiltration capabilities.
Impact at a Glance
Affected Business Functions
- Residential Internet Services
- Network Security Operations
- Customer Technical Support
- ISP Infrastructure Management
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of internal residential network devices including security cameras, network-attached storage (NAS) devices, administrative interfaces, and IoT appliances to unauthorized internet access through permanent port-forwarding rules.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement between IoT devices and critical network resources even when perimeter defenses are bypassed
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized outbound connections from compromised internal devices
- • Enable Multicloud Visibility & Control to monitor anomalous traffic patterns and suspicious port-forwarding activities across network infrastructure
- • Utilize Threat Detection & Anomaly Response capabilities to establish baselines for normal device behavior and alert on unauthorized remote access attempts
- • Apply Cloud Native Security Fabric (CNSF) for real-time inspection and distributed policy enforcement to prevent exploitation of network infrastructure vulnerabilities



