VU#756733: Retraction of "Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability"
Cybersecurity Classified by Officially
Overview
The Calix GS7 XGS GS5239XG router running firmware EXOS/6.6.47 contains a missing authentication vulnerability that exposes its UPnP (Universal Plug and Play) WANIPConnection service on the public WAN interface
After further analysis of the case alongside the Calix security team, we have determined that this is not a valid vulnerability, based on testing and evidence currently available. The reported behavior was investigated across multiple device models, firmware releases, and environment configurations, but all relevant security controls performed as designed and the vulnerability could not be reproduced. Please see the bottom of this vulnerability note for Calix's formal Vendor Statement and additional methodology details.
Description
Calix GS7 XGS GS5239XG is a residential gateway that provides routing, NAT, and firewall functionality for home networks. The device includes the Universal Plug and Play (UPnP) service implemented via MiniUPnPd 2.3.7, a lightweight software program that provides features such as automatic port forwarding for applications and devices on the LAN. By default, the UPnP service is exposed on the device’s WAN interface and does not require authentication.
CVE-2026-75501 In affected firmware versions, the router binds its UPnP WANIPConnection SOAP service to the public WAN interface on TCP port 5000. Because the service does not require authentication when accepting SOAP requests, a remote attacker can obtain full access to the router’s critical UPnP functions including adding, deleting, and enumerating NAT port mappings.
Impact
This is an extract. The publication continues at the source.
Read the original at the source: https://kb.cert.org/vuls/id/756733
Officially imported this from CERT Coordination Center’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
This publication has changed since it was first published
2 versions recorded. The original is kept in full — nothing is overwritten.
- v2 imported change on current
- v1 as first published on
Provenance
- Organization
- CERT Coordination Center — imported from official source
- Official source
- https://www.kb.cert.org/vuls/atomfeed/ ATOM
- Imported
- September 15, 2026 20:57
- Versions
- 2 recorded
- Identity
https://kb.cert.org/vuls/id/756733