Impact
A flaw in the Calix GS7 XGS firmware allows unauthenticated remote attackers to modify NAT port‑forwarding rules via the UPnP WANIPConnection service. The MiniUPnPd control endpoint is exposed on the WAN interface on TCP port 5000 without any authentication or access control, which constitutes an improper access control weakness. By sending crafted SOAP requests an attacker can add, delete, or enumerate port mappings, or retrieve the external IP address. These actions enable a short‑circuit of the router’s firewall/NAT boundary, exposing internal LAN services directly to the public internet and potentially allowing further exploitation by the attacker.
Affected Systems
The affected device is the Calix GS7 XGS (GS5239XG) residential router. Version information is not listed, so all firmware releases of this model are considered potentially vulnerable unless a patch is applied.
Risk and Exploitability
The vulnerability carries high risk due to the lack of authentication on a service exposed to the WAN. EPSS score < 1% and CVSS score 7.5, but the potential impact—unauthorized manipulation of firewall rules and direct exposure of LAN services—justifies a high‑risk assessment. The likely attack vector is remote access over the WAN interface via TCP port 5000 where the MiniUPnPd listener is publicly reachable.
OpenCVE Enrichment