Unpatched Calix UPnP flaw exposes WAN SOAP on port 5000
CVE-2026-75501 is a missing-authentication bug in Calix GS7 XGS gateways on EXOS/6.6.47. MiniUPnPd’s WANIPConnection SOAP interface listens on WAN TCP 5000.

On August 24 BleepingComputer reported CVE-2026-75501, a missing-authentication flaw in Calix GS7 XGS gateways — models GS5239XG and GigaSpire 7u10txg — running EXOS/6.6.47. MiniUPnPd’s WANIPConnection SOAP interface is reachable on WAN TCP port 5000. There was no patch at publication.
What we know
- CVE-2026-75501 is missing authentication on Calix GS7 XGS (GS5239XG / GigaSpire 7u10txg) running EXOS/6.6.47.
- MiniUPnPd exposes WANIPConnection SOAP on WAN TCP 5000.
- Researcher Brian Khan Quintana found a no-expiry mapping that survived reboot.
- He notified Calix on June 7 and then CERT/CC.
- The hardware is used by Cox, Brightspeed, ALLO, CityFibre, and Conexon. The workaround is to disable UPnP; no patch was available at publication.
Takeaways
- The SOAP control plane is on the WAN, not only behind NAT.
- A mapping that outlives reboot is a durable hole, not a one-shot leak.
- Operators are being told to turn UPnP off while they wait for a patch.
Source: BleepingComputer


