Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
Chinese hackers exploited ZyXEL CVE-2026-7273 on GS1900 switches in 48 countries; CISA added it to KEV.
GreyNoise says a Chinese threat actor exploited CVE-2026-7273, an unauthenticated stack-based buffer overflow (CVSS 8.8) in ZyXEL GS1900 switches, against devices in 48 countries in August. An obfuscated Python script pulled hashed root credentials, configuration, and network data from 996 devices; 564 still used factory-default credentials. ZyXEL patched ten GS1900 models in June, and CISA added the flaw to the KEV catalog with a three-day federal deadline under BOD 26-04. The same actor chained Ubiquiti bugs for remote code execution, targeted WordPress in July, stole over 18,000 records from a Western government body, and is assessed as Red Heron or closely related.
- CVE-2026-7273 is an unauthenticated stack overflow in ZyXEL GS1900 switches, CVSS 8.8.
- A Chinese group hit devices in 48 countries in August and stole data from 996 switches.
- 564 compromised devices still used factory-default credentials.
- CISA added the bug to KEV, giving agencies three days to patch under BOD 26-04.
- GreyNoise links the actor to Red Heron and separate Ubiquiti and WordPress attacks.
Vulnerabilities mentionedAll →
- CVE-2026-72738.83%Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerabilitypublished · Zyxel GS1900 Series Switches KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article334 words · extracted from securityweek.com · click to collapse
A Chinese threat actor has been targeting vulnerable ZyXEL GS1900 switches worldwide for sensitive information exfiltration, threat intelligence firm GreyNoise warns.
Tracked as CVE-2026-7273 (CVSS score of 8.8), the security defect is described as a stack-based buffer overflow that could be exploited without authentication to execute OS commands via crafted HTTP requests.
ZyXEL rolled out security updates patching the bug in ten GS1900 switch models in June. On Monday, GreyNoise warned that it was exploited by a Chinese hacking group in August against ZyXEL devices in 48 countries.
The threat actor used a heavily obfuscated Python script to exfiltrate sensitive information such as hashed root credentials, configuration details, and networking information from 996 vulnerable devices.
“While the script explicitly targets firmware versions 2.10-2.90 of the GS1900-24, it does provide command-line options (e.g., libc base address, global offsets) for targeting other firmware in scope for the vulnerability,” GreyNoise says.
While the hackers extracted hashed credentials, 564 of the compromised devices had factory default credentials, leaving the door open to future attacks.
Advertisement. Scroll to continue reading.
On Monday, the US cybersecurity agency CISA added CVE-2026-7273 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days, as mandated by BOD 26-04.
The same threat actor was also seen using a chain of Ubiquiti vulnerabilities leading to remote code execution (RCE), and targeting WordPress installations in July, in attacks against small business and government entities.
“The most egregious data theft occurred against an identified western governmental organization involving more than 18,000 sensitive records stolen from its backend database,” GreyNoise says.
The cybersecurity firm believes that the threat actor is the same as or closely related to the Red Heron hacking group that Acronis observed exploiting a Gitea vulnerability in attacks targeting hundreds of systems worldwide.
Related: WordPress Patches ‘Click2Shell’ Vulnerability
Related: Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
Related: In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
Related: CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot