VU#756733: Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability
2026-08-21T20:52:01Z•cf0e7e46c171ac63ebc82714bda602a711dd56d37e07bfaa071f732eaa9408c9
CVE-2026-16503CVE-2026-16504CVE-2026-18412CVE-2026-18497CVE-2026-19505CVE-2026-19506CVE-2026-6726CVE-2026-6727CVE-2026-75501CVE-2026-8496CERT/CCOpenCartRDK-BSOGoTPMTrueTypeUPnPWebUIXSSactively-exploitedauthentication-bypasscloud-deploymentdefault-credentialsdirectory-traversalheap-buffer-overflowinformation-disclosuremisconfigurationmissing-authenticationmultiple-vulnerabilitiesnetwork-exposureremote-code-executionrouterside-channel
What happened
CERT/CC advisories describe multiple 2026 vulnerabilities affecting residential routers, broadband gateway WebUIs, TPM 2.0 reference code, OpenCart, the stb TrueType library, SOGo, and VPS.org deployment templates. Impacts include unauthenticated administrative access, NAT/firewall bypass, authentication bypass, denial of service, information disclosure, cryptographic key compromise, arbitrary code execution, XSS-driven mailbox compromise, and exposure of services through default credentials and insecure network bindings. Several issues lack vendor patches; affected systems should be upgraded,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- cf0e7e46c171ac63ebc82714bda602a711dd56d37e07bfaa071f732eaa9408c9
- Enrichment time
- 2026-08-21T20:52:01Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.