Unpatched Calix router flaw lets attackers expose devices behind home networks
An unpatched flaw in Calix residential routers used by several US broadband providers lets a remote, unauthenticated attacker create port-forwarding rules that expose devices on the local network to the internet. Tracked as CVE-2026-75501, the missing-authentication issue affects the Calix GS7 XGS model on a specific firmware version, and Calix supplies gear to large providers including Cox and Brightspeed. The researcher who found it reported it to the vendor in June, got no response, and disclosed through CERT/CC after further attempts failed. Because it lets an attacker punch holes through the router's network address translation, internal devices that were never meant to be reachable can be exposed. No fix is available.
- Check
- If you operate or manage affected Calix broadband routers, ask the provider or vendor about a fix and mitigations, and check devices for unexpected port-forwarding rules exposing internal systems.
- Affected
- Networks behind affected Calix GS7 XGS routers on the vulnerable firmware (CVE-2026-75501); a remote, unauthenticated attacker can add port-forwarding rules that expose internal devices to the internet, and no patch exists.
- Fix
- Press the broadband provider and Calix for a firmware fix, restrict remote management where possible, monitor for unauthorized port-forwarding entries, and place sensitive internal devices behind an additional firewall until resolved.