VU#756733: Retraction of "Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability"
Imported from official source
Overview The Calix GS7 XGS GS5239XG router running firmware EXOS/6.6.47 contains a missing authentication vulnerability that exposes its UPnP (Universal Plug and Play) WANIPConnection service on the public WAN interface After further analysis of the case alongside the Calix security team, we have determined that this is not a valid vulnerability, based on testing and evidence currently available. The reported behavior was investigated across multiple device models, firmware releases, and environment configurations, but all relevant security controls performed as designed and the vulnerability could not be reproduced. Please see the bottom of this vulnerability note for Calix's formal Vendor Statement and additional methodology details. Description Calix GS7 XGS GS5239XG is a residential gateway that provides routing, NAT, and firewall functionality for home networks. The device includes the Universal Plug and Play (UPnP) service implemented via MiniUPnPd 2.3.7, a lightweight software program that provides features such as automatic port forwarding for applications and devices on the LAN. By default, the UPnP service is exposed on the device’s WAN interface and does not require a...
This version
- Version
- 2 of 2
- Recorded
- September 18, 2026 09:42
- Change
- Imported change
- Content hash
620b750e3f60a8488ba78cfb03e20a10- All versions
- Revision history