SEPTEMBER 21, 2026
Live Feed
Back to database
Case File

CVE-2026-75501

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-20

CyberRota Analysis

AI-Generated

The Calix EXOS firmware for the GS7 XGS residential router is vulnerable due to the exposure of the MiniUPnPd control endpoint on the WAN interface, allowing unauthenticated remote attackers to manipulate NAT port-forwarding rules via crafted SOAP requests. This could lead to the bypassing of firewall protections, potentially exposing internal LAN services to the public internet. Organizations using this router model should prioritize addressing this vulnerability to safeguard their network infrastructure.

CVE
CVE-2026-75501
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A

Original NVD Description

Rejected reason: Vendor could not replicate the vul, and reporter is unavailable to comment.