A flaw tracked as CVE-2026-75501 in the Calix GigaSpire UPnP vulnerability disclosure has left an unpatched hole in a premium residential gateway used by customers of several major US broadband providers, allowing anyone on the public internet to silently punch through its firewall without a password. No fix exists, and the device ships with the risky configuration switched on by default.
What the Calix GigaSpire UPnP vulnerability actually does
The affected hardware is the GS5239XG (also marketed as the GigaSpire 7u10txg), a Wi-Fi 7 gateway with an integrated XGS-PON fibre terminal. The device runs EXOS/6.6.47 firmware and, according to TechTimes, uses MiniUPnPd 2.3.7 as its UPnP daemon. The problem is not the daemon itself but where it listens: rather than binding exclusively to the internal LAN, the router exposes its UPnP WANIPConnection SOAP service on the public WAN interface at TCP port 5000, with no access controls whatsoever.
That means anyone with an internet connection can send unauthenticated SOAP requests to the device and instruct it to create, delete or enumerate port-forwarding rules, or retrieve the router’s external IP address. In practice, the flaw lets a remote attacker bypass the router’s Network Address Translation (NAT) and firewall protections to expose whatever sits on the home network: cameras, network-attached storage (NAS) devices, administrative interfaces, IoT appliances. Researcher Brian Khan Quintana, who discovered the flaw, put it plainly: ‘One unauthenticated request from anywhere in the world is enough to open a permanent hole through the router’s firewall to any device inside the house. No password. No prompt. Nothing on screen. The rule survives a reboot.’
Quintana confirmed that last point empirically. He sent a request from outside his home network to create a port mapping with no expiration time; after power-cycling the router, the mapping remained active.
Two months of silence before CERT/CC went public
Quintana first attempted to notify Calix on 7 June. Receiving no substantive response, he escalated to the Carnegie Mellon CERT Coordination Center, which coordinated disclosure after Calix again failed to engage meaningfully. According to TechTimes, CERT/CC formally disclosed CVE-2026-75501 on 21 August, more than two months after Quintana’s initial contact. Quintana then published the full technical details himself.
CERT/CC’s advisory is direct about the exposure: ‘In affected firmware versions, the router binds its UPnP WANIPConnection SOAP service to the public WAN interface on TCP port 5000.’ The centre confirmed that an attacker can add or delete port mappings, enumerate existing ones, and query the external IP address from anywhere on the internet.
Calix works with US broadband providers including Cox Communications, Brightspeed, ALLO, CityFibre and Conexon, which gives the affected hardware a broad installed base. BleepingComputer contacted Calix for comment and had not received a response by the time of publication.
Shipped hot: UPnP on by default
The exposure is compounded by one detail that SecurityOnline flags directly: devices ship with UPnP enabled by default, which means the overwhelming majority of units in the field are carrying this configuration straight out of the box, without any action from the owner or the ISP.
With no patch available, Quintana’s recommended workaround is to disable UPnP through the router’s administrative interface, via Advanced, then Security, then UPnP. The trade-off is real: some games rely on automatic port opening, though manual port forwarding remains possible for specific services. CERT/CC adds a practical caveat: the UPnP setting may be locked on provider-managed devices, in which case users should contact their ISP and request deactivation directly.
What an attacker can do
Quintana’s disclosure lists the specific capabilities the flaw hands to an unauthenticated remote attacker: creating arbitrary port-forwarding rules; deleting existing mappings; enumerating all current mappings; and retrieving the router’s public IP address. Each of those actions requires only a single SOAP request and leaves no visible indication on the router’s administrative interface.
Until Calix issues a firmware update addressing the Calix GigaSpire UPnP vulnerability, the only reliable protection available to end users is disabling UPnP entirely. Customers who find the setting greyed out should raise the issue with their broadband provider, since it is the ISP, in most cases, that manages device configuration remotely.

