Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Calix GigaSpire Routers Have an Unpatched Hole That Lets Strangers Open Your Firewall Remotely

A vulnerability disclosed on August 21 by the Carnegie Mellon CERT Coordination Center means someone with an internet connection and no login credentials can remotely reconfigure the firewall on a popular fiber router, according to CERT/CC's advisory (VU#756733) and reporting from BleepingComputer.
The flaw, tracked as CVE-2026-75501, hits the Calix GS5239XG, sold to broadband providers as the GigaSpire 7u10txg. It's Calix's flagship Wi-Fi 7 gateway with a built-in XGS-PON fiber terminal, according to Tech Times, which pulled specs from Calix's own product page. The affected firmware is EXOS/6.6.47.
What's Actually Broken
The router exposes something called the MiniUPnPd control endpoint on its public-facing WAN interface, over TCP port 5000, with zero access controls, according to CERT/CC's advisory as cited by BleepingComputer. In plain terms: the router's UPnP service, which is supposed to only talk to devices inside your home network, is instead listening to the entire internet.
That means anyone, anywhere, can send the router a SOAP request to add, delete, or list port-forwarding rules, or to pull the device's external IP address, per CERT/CC. No password. No authentication check. No notification on screen.
Security researcher Brian Khan Quintana, who found and reported the bug, put it bluntly in comments carried by BleepingComputer: "One unauthenticated request from anywhere in the world is enough to open a permanent hole through the router's firewall to any device inside the house. No password. No prompt. Nothing on screen. The rule survives a reboot."
Quintana says he tested this himself, sending requests from outside his home network that created a port mapping exposing an internal device. The mapping had no expiration and survived a full power cycle, according to his findings as reported by BleepingComputer.
The practical risk: an attacker can forward a public port straight to an internal security camera, a network-attached storage box, a router's own admin panel, or any other device on the home network, bypassing the NAT and firewall protections that are supposed to keep that traffic out.
Disclosure Timeline and Vendor Silence
Quintana tried to notify Calix directly starting June 7, according to BleepingComputer. Calix did not respond. Quintana then escalated to CERT/CC, which made multiple additional attempts to reach the vendor before coordinating public disclosure more than two months later, on August 21.
As of this writing, Calix has issued no public statement, no patch, and no firmware update timeline, according to both Tech Times and BleepingComputer. CERT/CC's advisory documents the vendor's non-response as part of the official record.
A separate flaw, CVE-2026-19746, affecting Calix GigaSpire 26.1.0 firmware, was published August 14 and involves a denial-of-service bug in the traceroute.cmd function, according to vulnerability tracker Strobes VI. Strobes rates that one low severity, with a CVSS score of 0.0 and no known public exploits, but notes the same pattern: the vendor was contacted early and did not respond, and no patch has been released.
Why Customers Can't Just Fix It Themselves
These aren't devices consumers bought and control. Calix supplies equipment to more than 1,000 broadband providers across the U.S., according to Tech Times. Providers identified by BleepingComputer as deploying Calix gear include Cox Communications, Brightspeed, ALLO, CityFibre, and Conexon. Cox alone reported roughly 6.9 million broadband subscribers as of 2026, per Tech Times.
ISPs provision these routers remotely and frequently lock down the admin settings so customers can't change them. CERT/CC's advisory explicitly acknowledges the UPnP toggle "might be locked" on some deployments, meaning the one workaround available, disabling UPnP through the admin panel under Advanced, Security, UPnP, isn't accessible to everyone who needs it.
Quintana recommends disabling UPnP as a stopgap for anyone who can. He notes the tradeoff: doing so breaks automatic port-opening that some online games and applications rely on, though specific ports can still be opened manually.
For customers locked out of that setting, the fix depends entirely on two things that haven't happened: Calix shipping a firmware update, or the ISP pushing a carrier-level configuration change. Neither has occurred as of August 25.
No information is available in CERT/CC's advisory or Calix's own materials about how many devices are actively deployed with this configuration, or whether any ISP has begun pushing an interim mitigation on its own network. Subscribers of Cox, Brightspeed, ALLO, CityFibre, or Conexon who use fiber gateway equipment have no public channel yet to confirm whether their specific unit is affected or whether their provider has taken action.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.