TTO-2026-0825-001 · August 25, 2026 Unpatched

Unpatched Calix CVE-2026-75501 Lets Unauthenticated Attackers Bypass NAT and Expose Home Network Devices to the Internet

calix.comCVE-2026-75501UPnP WANIPConnectionWAN interface port 5000No authenticationNAT bypassGS7 XGS GS5239XGNo public patchISP-deployed devices

Summary

CERT/CC published a vulnerability note on August 22, 2026 for CVE-2026-75501, an unauthenticated missing-authentication vulnerability in the Calix GS7 XGS GS5239XG residential gateway that allows any attacker with internet access to bypass the router's network address translation and expose devices on the internal home network directly to the public internet. The Calix GS7 XGS GS5239XG is a residential gateway deployed by internet service providers across the Americas, including the United States, to serve home broadband subscribers. It provides routing, NAT, and firewall functionality for home networks. The vulnerability exists because the router binds its Universal Plug and Play WANIPConnection SOAP service to the public WAN interface on TCP port 5000, and the service accepts SOAP requests without requiring authentication. A remote attacker can send crafted SOAP requests to add, delete, or modify port forwarding rules on the device without any credentials, effectively punching holes in the NAT firewall that expose specific internal devices — computers, cameras, smart home devices, NAS drives — to direct inbound connections from anywhere on the internet. ISP customers generally have no way to identify this exposure and no mechanism to patch the device themselves. Calix confirmed awareness of the vulnerability but has not released a public patch or published a public advisory, consistent with the company's stated policy of not pursuing CVE disclosures or public vulnerability communications for ISP-deployed equipment. Calix's position is that firmware updates are distributed to ISPs through internal channels, and ISPs are responsible for deploying those updates to customer premises equipment.

Timeline

DateEvent
Feb 2025Researcher Danilo Erazo discovers five zero-day vulnerabilities in Calix GigaCenter ONT devices
Jul 18, 2025Calix releases firmware patch to customers through internal advisory — no public disclosure
Jul 21, 2025CVE reserved for five GigaCenter vulnerabilities
Aug 22, 2026CERT/CC publishes VU#756733 for CVE-2026-75501 — Calix GS7 XGS GS5239XG UPnP NAT bypass
Aug 22, 2026No public patch available for CVE-2026-75501 — Calix does not publish vulnerability advisories per company policy
Aug 25, 2026ISP-deployed devices remain exposed — no consumer remediation path

Domain Intelligence

DomainScoreDKIMSPFDMARCStatus
calix.com60.63Live
WarmBadge Intelligence Snapshot · Captured: August 25, 2026 UTC

Context

calix.com scores 60.63 — a low-trust range score for a company whose hardware sits inside millions of home networks across the Americas, deployed and managed entirely through internet service providers. Calix's decision not to publish vulnerability advisories or pursue CVE disclosures for ISP-deployed equipment is a policy choice that keeps security information inside the ISP supply chain and away from the subscribers whose home networks those devices protect. The subscribers have no way to know they are exposed, no way to patch the device themselves, and no way to know whether their ISP has deployed a fix. The practical remediation path for CVE-2026-75501 is blocking TCP port 5000 at the ISP network edge before traffic reaches the affected devices — a mitigation available to ISPs, not subscribers.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · August 25, 2026