Calix Home Routers Have a Hole That Lets Strangers Punch Into Your Network
A flaw in Calix GS7 XGS (model GS5239XG) home routers, handed out by several U.S. internet providers, lets anyone on the internet quietly open doors into a customer's home network. No patch yet.

Key points
- A flaw in Calix GS7 XGS (model GS5239XG) home routers lets anyone on the internet add port-forwarding rules without a password.
- Port forwarding decides which devices inside a home can be reached from outside, so this hands attackers a direct path in.
- The routers are supplied by several U.S. Broadband providers to their residential customers.
- Calix has not released a fix at the time of writing.
- Home users can't patch this themselves; the fix has to come from Calix and their internet provider.
There's a security bug in a widely used home router that needs no password, no clever trick, and no physical proximity to your house.
The router is the Calix GS7 XGS, sold under the model number GS5239XG. It's the box that sits in the corner of the living room and gives the whole house internet. Several U.S. Broadband providers ship it to residential customers as standard kit.
The flaw, first reported by BleepingComputer, lets a remote attacker add port-forwarding rules over the internet with no login required. We covered a structurally similar no-patch situation in July, when a hidden backdoor in Tenda routers handed full administrative control to anyone who knew the right credential.
What is port forwarding, in plain English?
Port forwarding decides which devices inside your home can be reached from the outside world. Normally your router acts as a bouncer: things inside can call out, but the outside can't call in.
A port-forwarding rule pokes a hole in that line. It says, in effect, "anyone knocking on this specific door, send them straight to the security camera in the hallway." Used properly, it's how people reach their own cameras or game servers from the road.
Used by an attacker, it's how a stranger reaches your printer or the laptop where you do your banking.
How bad is this, really?
Bad, because the attacker doesn't need your Wi-Fi password or your router password. They just need to reach the router over the internet, which for a residential broadband customer is the default state of affairs.
Once a rule is in place, any device on the home network the attacker chose to expose is sitting on the public internet. Old cameras with default credentials, network storage drives full of family photos: fair game.
The failure mode here is a router accepting configuration changes without asking who's making them. That's a category of bug the industry has been fixing since the mid-2000s. Seeing it in 2025 kit shipped to homes is grim.
Is there a patch?
No. At the time of writing, Calix hasn't released a fix. Home users can't solve this themselves. The update has to come from Calix and be pushed by the internet provider.
| Detail | What we know |
|---|---|
| Affected device | Calix GS7 XGS, model GS5239XG |
| Who uses it | Multiple U.S. Broadband providers, residential customers |
| Attack needs a password? | No |
| Attacker needs to be nearby? | No, remote over the internet |
| Patch available? | Not yet |
Should you worry?
Call your internet provider with two questions: is my router a Calix GS7 XGS, and when will you push a fix for the port-forwarding vulnerability?
If you have sensitive devices at home, cameras or a home office setup, power down the ones you don't actively need until this is patched. Check the router's port-forwarding page and note anything listed that you didn't configure yourself.
The post-mortem on incidents like this always says the same thing: unauthenticated config endpoints on customer-premises equipment are a solved problem, and shipping them anyway is a choice.
If you run a fleet of these, assume rules can be added out-of-band and monitor for forwarding entries you didn't create.



