VU#756733: Calix GS7 XGS GS523... Note

VU#756733: Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability

The Calix GS7 XGS GS5239XG router, running firmware EXOS/6.6.47, has a critical security flaw. This vulnerability affects its UPnP service, specifically the WANIPConnection aspect. The UPnP service is exposed on the router's public WAN interface without any authentication required. This means a remote attacker can interact with the UPnP service without needing credentials. They can gain full control over the router's essential UPnP functions. This includes the ability to add, delete, and view NAT port mappings. By manipulating these mappings, an attacker can bypass NAT and firewall protections. This action exposes devices on the internal network to the public internet. Residential users are at high risk due to the default UPnP enabled configuration. A vendor patch is not yet available, but users can disable UPnP if possible. If disabling is not an option, contacting the ISP for deactivation might be necessary. Another mitigation involves filtering inbound traffic to TCP port 5000.