Stack-Based Buffer Overflow in Zyxel GS1900-48HPv2 Firmware
CVE-2026-7273

8.8HIGH

What is CVE-2026-7273?

A stack-based buffer overflow vulnerability exists in the CGI program of Zyxel's GS1900-48HPv2 switch firmware, which could be exploited by an unauthenticated attacker on the local network. This flaw allows for potentially executing operating system commands through specially crafted HTTP requests, posing a significant security risk for affected devices.

Affected Version(s)

GS1900-10HP firmware <= 2.90(AAZI.1)C0

GS1900-16 firmware <= 2.90(AAHJ.1)C0

GS1900-24 firmware <= 2.90(AAHL.1)C0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.