An unpatched vulnerability in Calix GS7 XGS residential routers can let remote attackers expose devices inside a home network to the public internet, according to BleepingComputer. The report says the flaw affects the Calix GS5239XG running EXOS/6.6.47 firmware and is tracked as CVE-2026-75501. The issue is a missing-authentication flaw in how the router exposes a MiniUPnPd control endpoint. BleepingComputer, citing CERT/CC, reports that affected firmware binds the UPnP WANIPConnection SOAP service to the public WAN interface on TCP port 5000 without access controls. That matters because Universal Plug and Play (UPnP) can be used to create port mappings: rules that forward traffic from the internet to a device behind the router. In the normal consumer-router model, Network Address Translation (NAT) and firewall defaults help keep devices such as cameras, network-attached storage boxes, administrative interfaces, and Internet of Things appliances from being directly reachable from the public web. The reported Calix flaw can let an unauthenticated attacker create those mappings remotely. BleepingComputer reports that attackers could send unauthenticated SOAP requests to add, delete, or enumerate port mappings, or query the router’s external IP address. Security researcher Brian Khan Quintana, who discovered the flaw, tested the issue by sending requests from outside his home network to create a mapping to an internal address. According to the report, a mapping configured with no expiration remained active after the router was power-cycled. The disclosure path is also notable. BleepingComputer says Quintana tried to notify Calix on June 7 and, after receiving no response, reported the vulnerability to Carnegie Mellon’s CERT Coordination Center. CERT/CC then coordinated public disclosure after multiple attempts to contact the vendor, and Quintana published technical details. Calix is a major supplier in the broadband-provider market. BleepingComputer reports that the company works with providers including Cox Communications, Brightspeed, ALLO, CityFibre, and Conexon. The affected GS5239XG is also marketed as the GigaSpire 7u10txg, a premium gateway device combining Wi-Fi 7 with an integrated XGS-PON fiber terminal. There is no fix described in the provided report. Quintana recommends that users of the vulnerable device disable UPnP through the administrative interface under Advanced Security UPnP. BleepingComputer notes that this can break automatic port opening used by some games, though users may be able to configure specific ports manually. CERT/CC also warns that the UPnP setting may be locked in some deployments. In those cases, users who cannot disable it themselves are advised to contact their internet service provider and ask for UPnP deactivation. BleepingComputer says it contacted Calix for comment on the flaw, affected models, and patch plans, but had not received a response as of publication. Who benefits: Attackers benefit from any deployment where the vulnerable service is reachable and UPnP remains enabled. Defenders benefit from a clear interim control: disabling UPnP where the interface allows it. Who's exposed: Users of Calix GS5239XG routers running EXOS/6.6.47 firmware are the exposed population identified in the report. Customers whose ISPs lock router security settings may be dependent on provider action to disable UPnP or apply any future fix.