# Unpatched Calix router flaw can expose devices through NAT

_Published Monday, August 24, 2026 at 6:07 PM EDT · Security · Developing · Tier 1 — Major_

![Unpatched Calix router flaw can expose devices through NAT — Primary](https://www.bleepstatic.com/content/hl-images/2026/08/24/Calix.jpg)

A missing-authentication flaw in Calix GS7 XGS routers can let remote attackers create port-forwarding rules and expose local devices to the public internet, according to a researcher and CERT/CC. The issue, CVE-2026-75501, affects devices running EXOS/6.6.47 firmware and exposes a MiniUPnPd control endpoint on WAN port 5000. The source says no patch is available; it recommends disabling UPnP where possible.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/unpatched-calix-flaw-lets-hackers-bypass-nat-to-expose-internal-devices/)

---
Canonical: https://techandbusiness.org/newswire/Qt8Uthu8DgaCYaPj-8SvLZ
Published: 2026-08-24T22:07:38.561Z
Story chronology: 2026-08-24T21:14:30.000Z
Retrieved: 2026-10-09T05:23:21.070Z
Publisher: Tech & Business (techandbusiness.org)
