Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

August 25, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: bleepingcomputer.com

Threat Risk: High
Victim: Residential broadband users
Incident: An unpatched authentication bypass in Calix routers allows remote port-forwarding configuration.
Impact: Internal network devices and IoT hardware can be exposed directly to the public internet.
Attacker: Unidentified threat actors
Analysis: The vulnerability stems from the MiniUPnPd control endpoint being exposed on the WAN interface without access controls. Attackers can send SOAP requests to create permanent port-forwarding rules, effectively neutralizing the router’s NAT protections. Because the flaw remains unpatched in premium Wi-Fi 7 gateways, it poses a significant risk to residential privacy and security.
Recommendations: Disable UPnP via the administrative interface under Advanced Security settings.; Audit internal network devices for unexpected public exposure.; Monitor for unauthorized traffic originating from or targeting TCP port 5000.
Source: BleepingComputer

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *