Skip to main content

CISA says Calix EXOS 6.6.47 exposes UPnP WANIPConnection on TCP 5000

The Calix GS7 XGS GS5239XG residential gateway running firmware EXOS/6.6.47 contains a missing authentication issue that exposes its UPnP WANIPConnection service on the public WAN interface, enabling unauthenticated remote access to UPnP functions.

Calix GS7 XGS GS5239XG provides routing, NAT, and firewall functionality for home networks. The device includes the Universal Plug and Play (UPnP) service implemented via MiniUPnPd 2.3.7, which provides features such as automatic port forwarding for applications and devices on the LAN. By default, the UPnP service is exposed on the device’s WAN interface and does not require authentication. CVE-2026-75501 describes that, in affected firmware versions, the router binds its UPnP WANIPConnection SOAP service to the public WAN interface on TCP port 5000. Because the service does not require authentication when accepting SOAP requests, a remote attacker can obtain full access to critical UPnP functions, including adding, deleting, and enumerating NAT port mappings.

CVE-2026-75501 enables an unauthenticated, remote attacker to remotely query and manipulate existing NAT mappings. Exploiting the vulnerability to create arbitrary port-forwarding rules on the router can bypass NAT and firewall protections and expose internal LAN devices to the public internet. The issue is described as posing risk to residential users with network-connected internal devices such as security cameras, network-attached storage (NAS), and other IoT appliances because the Calix router is typically provisioned with its default UPnP-enabled configuration.

The CERT/CC was unable to reach Calix to coordinate this vulnerability. Until a vendor patch is available, the stated approach is to reduce exposure by disabling UPnP on the router’s administrative interface. If the UPnP setting is unavailable or locked, it may be necessary to contact an ISP to request deactivation at the carrier level. Filtering inbound traffic to TCP port 5000, either via the router itself, a secondary firewall, or through an ISP, is also described as a way to prevent external hosts from reaching the WANIPConnection service.

Thanks to Brian Khan Quintana for researching and reporting the vulnerability. The document was written by Molly Jaconski.

The original article was written by Molly Jaconski.