ZeroHour
CERT/CC Vulnerability Notespublished ()ingested

VU#756733: Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability

mediumVulnerabilityimportance 48
AI summary · glm-5.3-flash

CERT/CC warns Calix GS7 XGS GS5239XG routers on firmware EXOS/6.6.47 expose an unauthenticated UPnP WANIPConnection service on the public WAN interface.

CERT/CC issued VU#756733 for a missing authentication vulnerability in the Calix GS7 XGS GS5239XG residential gateway running EXOS/6.6.47. The device's UPnP service, implemented with MiniUPnPd 2.3.7, is exposed on the WAN interface by default and does not require authentication, potentially letting remote attackers alter port mappings through the WANIPConnection service. The flaw affects routing, NAT, and firewall functionality for home networks.

  • UPnP WANIPConnection service exposed on WAN without authentication
  • Affects firmware EXOS/6.6.47 using MiniUPnPd 2.3.7
  • Default configuration leaves the service publicly reachable
  • Tracked as CERT/CC vulnerability note VU#756733
Full article

Overview The Calix GS7 XGS GS5239XG router running firmware EXOS/6.6.47 contains a missing authentication vulnerability that exposes its UPnP (Universal Plug and Play) WANIPConnection service on the public WAN interface. Description Calix GS7 XGS GS5239XG is a residential gateway that provides routing, NAT, and firewall functionality for home networks. The device includes the Universal Plug and Play (UPnP) service implemented via MiniUPnPd 2.3.7, a lightweight software program that provides features such as automatic port forwarding for applications and devices on the LAN. By default, the UPnP service is exposed on the device’s WAN interface and does not require…

This source does not provide full text. Read it at kb.cert.org.