CVE Tools

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

BleepingComputerBy Bill Toulas

PoC publicCalix GS7 XGS

Our summary

Security researchers disclosed CVE-2026-75501, an unpatched missing authentication vulnerability affecting Calix GS7 XGS residential routers running EXOS/6.6.47 firmware. The flaw allows remote attackers to bypass Network Address Translation and firewall protections by sending unauthenticated SOAP requests to the exposed MiniUPnPd control endpoint on the WAN interface. This enables threat actors to create permanent port-forwarding rules that expose internal assets, such as IP cameras and NAS devices, to the public internet without vendor remediation.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store