
An unpatched flaw in Calix GS7 XGS residential routers (also sold as the GigaSpire 7u10txg) lets attackers remotely add port-forwarding rules without any authentication, effectively bypassing the router’s built-in NAT and firewall. The bug, CVE-2026-75501, was discovered by researcher Brian Khan Quintana and reported to BleepingComputer. Because port-forwarding rules can be added silently and permanently, internal devices — security cameras, network-attached storage drives, smart home gadgets — can be pushed out to the public internet without the homeowner ever knowing.
The flaw lives in the router’s UPnP control endpoint, which is exposed on the WAN (internet-facing) side at TCP port 5000 with no access controls at all. Normally, UPnP is only supposed to be reachable from within your home network. Calix routers distributed by Cox Communications, Brightspeed, ALLO, CityFibre, and Conexon are all confirmed to run the vulnerable firmware (EXOS/6.6.47). No patch is available from Calix as of publication.
How to check if you’re affected
Affected devices are Calix GS7 XGS routers running firmware version EXOS/6.6.47, distributed by Cox Communications, Brightspeed, ALLO, CityFibre, or Conexon. Check your router’s label or admin page (usually at 192.168.0.1) to confirm the model.
If you have one of these routers, disable UPnP: go to Advanced → Security → UPnP in the router’s admin interface and turn it off. Be aware that some ISP-managed routers lock this setting — if the option is greyed out or missing, contact your ISP and ask them to disable UPnP remotely.
