VU#756733: Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability

2026-08-21T20:52:01Zcf0e7e46c171ac63ebc82714bda602a711dd56d37e07bfaa071f732eaa9408c9
CVE-2026-16503CVE-2026-16504CVE-2026-18412CVE-2026-18497CVE-2026-19505CVE-2026-19506CVE-2026-6726CVE-2026-6727CVE-2026-75501CVE-2026-8496CERT/CCOpenCartRDK-BSOGoTPMTrueTypeUPnPWebUIXSSactively-exploitedauthentication-bypasscloud-deploymentdefault-credentialsdirectory-traversalheap-buffer-overflowinformation-disclosuremisconfigurationmissing-authenticationmultiple-vulnerabilitiesnetwork-exposureremote-code-executionrouterside-channel

What happened

CERT/CC advisories describe multiple 2026 vulnerabilities affecting residential routers, broadband gateway WebUIs, TPM 2.0 reference code, OpenCart, the stb TrueType library, SOGo, and VPS.org deployment templates. Impacts include unauthenticated administrative access, NAT/firewall bypass, authentication bypass, denial of service, information disclosure, cryptographic key compromise, arbitrary code execution, XSS-driven mailbox compromise, and exposure of services through default credentials and insecure network bindings. Several issues lack vendor patches; affected systems should be upgraded,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
cf0e7e46c171ac63ebc82714bda602a711dd56d37e07bfaa071f732eaa9408c9
Enrichment time
2026-08-21T20:52:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.