HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Unauthenticated Remote Exploit (CVE‑2026‑75501) Bypasses NAT on Calix GS7 XGS Residential Routers

A flaw in Calix GS7 XGS routers (CVE‑2026‑75501) lets attackers create permanent port‑forwarding rules without authentication, exposing internal devices. The vulnerability highlights the need for continuous control‑mapping and audit evidence to satisfy SOC 2 access‑control requirements.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 bleepingcomputer.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Unauthenticated Remote Exploit (CVE‑2026‑75501) Bypasses NAT on Calix GS7 XGS Residential Routers

What Happened – A vulnerability (CVE‑2026‑75501) in Calix GS7 XGS (model GS5239XG) residential routers allows an unauthenticated attacker to issue SOAP requests to the MiniUPnPd service on TCP 5000. The flaw lets the attacker create, delete, or enumerate port‑forwarding rules that persist across reboots, effectively opening a permanent hole through the router’s NAT/firewall and exposing internal devices to the Internet. No vendor‑issued fix exists at the time of disclosure.

Why It Matters for Compliance & Audit Readiness

  • The issue is a classic control‑gap: a network device is exposing a management interface without proper authentication, violating SOC 2 CC6.1 (Logical Access) and CC7.1 (System Operations) requirements.
  • Continuous evidence of configuration compliance is essential; without automated mapping and monitoring, organizations cannot demonstrate that critical infrastructure remains within defined security baselines.
  • Leveraging a control‑mapping platform provides audit‑ready documentation that the vulnerable service is disabled or mitigated, satisfying both internal policy and external auditor expectations.

Who Is Affected – U.S. broadband providers that deploy Calix GS7 XGS gateways (e.g., Cox Communications, Brightspeed, ALLO, CityFibre, Conexon) and their residential customers.

Recommended Actions

  • Immediately disable UPnP or the MiniUPnPd service on affected routers via the vendor’s management console.
  • Deploy network‑traffic monitoring to detect unauthorized port‑forwarding rules and alert on changes to TCP 5000.
  • Map the “unauthenticated management interface” control to SOC 2 requirements, collect continuous evidence of remediation, and retain logs as audit artifacts.
  • Track vendor communications for a future firmware patch; in the interim, consider segmentation or replacement of vulnerable hardware.

Source: BleepingComputer

Technical Notes – The vulnerability stems from the MiniUPnPd control endpoint being bound to the WAN interface without access controls (EXOS 6.6.47 firmware). Attackers send unauthenticated SOAP requests to WANIPConnection on TCP 5000, creating persistent port‑forwarding entries. No CVSS score was published yet, but the exploit is remote, unauthenticated, and results in a high impact.

📰 Original Source
https://www.bleepingcomputer.com/news/security/unpatched-calix-flaw-lets-hackers-bypass-nat-to-expose-internal-devices/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →