Unpatched Calix flaw lets hackers bypass NAT to expose internal devices
PoC publicCalix GS7 XGSOur summary
Security researchers disclosed CVE-2026-75501, an unpatched missing authentication vulnerability affecting Calix GS7 XGS residential routers running EXOS/6.6.47 firmware. The flaw allows remote attackers to bypass Network Address Translation and firewall protections by sending unauthenticated SOAP requests to the exposed MiniUPnPd control endpoint on the WAN interface. This enables threat actors to create permanent port-forwarding rules that expose internal assets, such as IP cameras and NAS devices, to the public internet without vendor remediation.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.