Unpatched Calix GS5239XG router flaw exposes home devices to internet
Researcher Brian Khan Quintana found that Calix's GS5239XG (GigaSpire 7u10txg) fiber gateway exposes its UPnP control service on the public WAN interface without authentication, tracked as CVE-2026-75501. Anyone online can send a single unauthenticated request to add or remove port-forwarding rules, letting them bypass NAT and firewall protections. Calix did not respond to disclosure attempts, so CERT/CC coordinated a public release of the details.