Unpatched Calix flaw lets hackers bypass NAT to expose internal devices
ID: d360fbe8-fe4d-51e8-81f3-f3269f45190e
STIX ID: report--d360fbe8-fe4d-51e8-81f3-f3269f45190e
Feed Name: Bleeping Computer
An unauthenticated remote vulnerability (CVE-2026-75501) in Calix GS5239XG residential gateways running EXOS/6.6.47 exposes the MiniUPnPd control endpoint on the WAN (TCP 5000), allowing attackers to create, delete, or enumerate port-forwarding rules and obtain the external IP — bypassing NAT/firewall protections and exposing internal devices; a proof-of-concept was published, no patch is available, and the recommended mitigation is to disable UPnP or contact the ISP if the setting is locked.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
