Unauthenticated Remote Exploit (CVE‑2026‑75501) Bypasses NAT on Calix GS7 XGS Residential Routers
What Happened – A vulnerability (CVE‑2026‑75501) in Calix GS7 XGS (model GS5239XG) residential routers allows an unauthenticated attacker to issue SOAP requests to the MiniUPnPd service on TCP 5000. The flaw lets the attacker create, delete, or enumerate port‑forwarding rules that persist across reboots, effectively opening a permanent hole through the router’s NAT/firewall and exposing internal devices to the Internet. No vendor‑issued fix exists at the time of disclosure.
Why It Matters for Compliance & Audit Readiness
- The issue is a classic control‑gap: a network device is exposing a management interface without proper authentication, violating SOC 2 CC6.1 (Logical Access) and CC7.1 (System Operations) requirements.
- Continuous evidence of configuration compliance is essential; without automated mapping and monitoring, organizations cannot demonstrate that critical infrastructure remains within defined security baselines.
- Leveraging a control‑mapping platform provides audit‑ready documentation that the vulnerable service is disabled or mitigated, satisfying both internal policy and external auditor expectations.
Who Is Affected – U.S. broadband providers that deploy Calix GS7 XGS gateways (e.g., Cox Communications, Brightspeed, ALLO, CityFibre, Conexon) and their residential customers.
Recommended Actions
- Immediately disable UPnP or the MiniUPnPd service on affected routers via the vendor’s management console.
- Deploy network‑traffic monitoring to detect unauthorized port‑forwarding rules and alert on changes to TCP 5000.
- Map the “unauthenticated management interface” control to SOC 2 requirements, collect continuous evidence of remediation, and retain logs as audit artifacts.
- Track vendor communications for a future firmware patch; in the interim, consider segmentation or replacement of vulnerable hardware.
Source: BleepingComputer
Technical Notes – The vulnerability stems from the MiniUPnPd control endpoint being bound to the WAN interface without access controls (EXOS 6.6.47 firmware). Attackers send unauthenticated SOAP requests to WANIPConnection on TCP 5000, creating persistent port‑forwarding entries. No CVSS score was published yet, but the exploit is remote, unauthenticated, and results in a high impact.