Critical flaw in Calix router enables unauthenticated remote firewall control

A serious security flaw in Calix’s GigaSpire 7u10txg home router allows attackers from the internet to modify firewall rules without login, raising urgent security concerns for ISP-managed devices and connected homes.

A critical flaw in Calix’s GigaSpire 7u10txg home router can let an attacker on the internet alter firewall rules without logging in, according to Carnegie Mellon’s CERT Coordination Centre. The weakness, tracked as CVE-2026-75501, affects the GS5239XG model running EXOS/6.6.47 and is particularly serious because many units are ISP-managed and locked down, leaving subscribers unable to apply a simple fix themselves.

CERT/CC said the router’s UPnP service is exposed in a way that allows unauthenticated requests from the WAN side, rather than only from inside the home network. In practical terms, that means an external attacker who knows a customer’s public IP address can create, delete or inspect port-forwarding rules and, in some cases, make those changes persist even after a reboot.

The technical root of the problem is straightforward. UPnP is meant to help devices on a trusted local network request temporary firewall exceptions, such as for gaming consoles or video calls. On the affected Calix firmware, however, the MiniUPnPd service listens on the public interface and accepts SOAP commands without authentication. Security researchers say that makes the router’s firewall function accessible to anyone who can reach the device over the internet.

Independent researcher Brian Khan Quintana said he found the flaw while examining his own ISP-supplied equipment and later followed responsible disclosure procedures. According to his account, he warned Calix, the relevant broadband provider and CERT/CC in June, then continued to press the issue when the vendor did not respond in a meaningful way. CERT/CC eventually published the advisory on 21 August and listed the vendor status as unknown. No patch timeline has been announced.

The risk is not limited to the router itself. A successful attacker could expose cameras, storage devices, home computers or other internet-connected systems behind the gateway. That is why this kind of flaw has long been treated as a serious residential-network problem: once a malicious port-forward is in place, the internal device can be reachable from anywhere, often with no obvious warning to the subscriber.

The problem is harder to contain when the device is supplied and provisioned by an internet service provider. CERT/CC noted that the UPnP setting may be locked in some cases, which means the customer cannot simply switch it off from the admin panel. Researchers said affected subscribers should check their port-forwarding tables, identify the model number on the unit and ask their ISP to disable UPnP or push a configuration update if they cannot do it themselves.

There is no confirmed exploitation of CVE-2026-75501 yet, but the attack path is simple enough that security teams are treating it as urgent. For customers, the immediate mitigation is to disable UPnP where possible and to look for any unfamiliar forwarding rules. If the setting is inaccessible, the burden falls on the ISP and Calix to deliver a firmware or configuration fix.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.