Calix Home Routers Have a Hole That Lets Strangers Punch Into Your Network
A flaw in Calix GS7 XGS routers, handed out by several U.S. internet providers, lets anyone on the internet quietly open doors into a customer's home network. No patch yet.

Key points
- A flaw in Calix GS7 XGS (model GS5239XG) home routers lets anyone on the internet add port-forwarding rules without a password.
- Port forwarding is the setting that decides which devices inside a home can be reached from outside, so this hands attackers a way in.
- The routers are supplied by several U.S. broadband providers to their residential customers.
- Calix has not released a fix at the time of writing, and the vulnerability is unpatched.
- Home users cannot patch this themselves; the fix has to come from Calix and their internet provider.
There is a security bug in a widely used home router that does not need a password, does not need any clever trick, and does not need the attacker to be anywhere near your house.
The router is the Calix GS7 XGS, sold under the model number GS5239XG. It is the little box that sits in the corner of the living room and gives the whole house internet. Several U.S. broadband providers ship it to their residential customers as the standard piece of kit.
The flaw, first reported by BleepingComputer, lets a remote attacker add port-forwarding rules to the router over the internet, with no login required.
What is port forwarding, in plain English?
Port forwarding is the setting that decides which devices inside your home can be reached from the outside world. Normally, your router acts as a bouncer: things inside can call out, but the outside cannot call in.
A port-forwarding rule pokes a hole in that bouncer's line. It says, in effect, "anyone knocking on this specific door, send them straight to the security camera in the hallway." Used properly, it is how people access their own home cameras or game servers from the road.
Used by an attacker, it is how a stranger reaches your printer, your smart lock, your baby monitor, or the laptop where you do your banking.
How bad is this, really?
Bad, because the attacker does not need to know your Wi-Fi password, your router password, or anything else. In practice, they just need to reach the router over the internet, which for a residential broadband customer is the default state of affairs.
Once a rule is in, any device on the home network that the attacker chose to expose is now sitting on the public internet. Old security cameras with default passwords, network storage drives full of family photos, work laptops with open file shares: any of them are fair game.
The failure mode here is a router accepting configuration changes without asking who is making them. That is a category of bug the industry has been fixing since the mid-2000s. Seeing it in 2025 kit shipped to millions of homes is grim.
Is there a patch?
No. At the time of writing, Calix has not released a fix. That leaves home users in the awkward position of not being able to solve this themselves. The update has to come from Calix and be pushed by the internet provider.
| Detail | What we know |
|---|---|
| Affected device | Calix GS7 XGS, model GS5239XG |
| Who uses it | Multiple U.S. broadband providers, residential customers |
| Attack needs a password? | No |
| Attacker needs to be nearby? | No, remote over the internet |
| Patch available? | Not yet |
What should customers actually do?
Call your internet provider and ask two questions. First: is my router a Calix GS7 XGS? Second: when will you push a fix for the port-forwarding vulnerability?
If you have sensitive devices at home, cameras, smart locks, a home office setup, unplug or power down the ones you do not actively need until this is patched. Check the router's port-forwarding page (your provider's support line can walk you through it) and note anything already listed that you did not set up yourself.
One thing the post-mortem will say: unauthenticated config endpoints on customer-premises equipment are a solved problem, and shipping them anyway is a choice.
Operational takeaway: if you run a fleet of these, assume rules can be added out-of-band and monitor for forwarding entries you did not create.



