Stack-Based Buffer Overflow in Zyxel GS1900-48HPv2 Firmware
CVE-2026-7273
Key Information:
- Vendor
Zyxel
- Vendor
- CVE Published:
- 16 June 2026
Badges
What is CVE-2026-7273?
CVE-2026-7273 is a significant vulnerability found in the firmware of the Zyxel GS1900-48HPv2, a network switch utilized in various organizational infrastructures for managing network traffic. This vulnerability manifests as a stack-based buffer overflow within the device's CGI program, affecting firmware versions up to 2.90(ABTQ.1)C0. It allows unauthenticated attackers on the local network (LAN) to exploit the vulnerability by sending specially crafted HTTP requests. If successfully exploited, this flaw could enable attackers to execute arbitrary operating system commands, thereby compromising the integrity and security of the affected device and the broader network it's connected to.
Potential impact of CVE-2026-7273
-
Unauthorized Remote Code Execution: Successful exploitation can lead to unauthorized access to the switch, allowing attackers to execute arbitrary commands, which could encompass modifying network configurations or deploying malware.
-
Network Disruption and Data Breach: The ability to manipulate network switch operations can result in network outages or instability, leading to service disruptions. Additionally, sensitive data traversing the network may be at risk, escalating the potential for data breaches.
-
Increased Vulnerability to Further Attacks: By compromising a network switch, attackers could gain footholds within the organization’s network, facilitating lateral movement and potentially allowing access to other critical systems or sensitive resources, increasing the overall attack surface.
CISA has reported CVE-2026-7273
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-7273 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace as recent news articles suggest the vulnerability is being used by ransomware groups.
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected Version(s)
GS1900-10HP firmware <= 2.90(AAZI.1)C0
GS1900-16 firmware <= 2.90(AAHJ.1)C0
GS1900-24 firmware <= 2.90(AAHL.1)C0
News Articles
Week in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents - Help Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Know what was tested before your SAP ECC migration goes
2 days ago
CISA orders feds to patch Zyxel flaw exploited for data theft
Attackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
1 week ago
Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
CISA added Zyxel CVE-2026-7273 to KEV after active exploitation, while Arctic Wolf reported attacks on a Veeam Windows flaw.
1 week ago
References
CVSS V3.1
Timeline
- 💰
Used in Ransomware
- 📰
First article discovered by The Hacker News
- 👾
Exploit known to exist
- 🦅
CISA Reported
Vulnerability published
Vulnerability Reserved