CISA Flags Actively Exploited Flaw in Zyxel GS1900 Switches
CISA added actively exploited stack buffer overflow CVE-2026-7273 in Zyxel GS1900-48HPv2 switches to its KEV catalog with a September 24 remediation deadline.
CISA added CVE-2026-7273, a stack-based buffer overflow in the CGI program of Zyxel GS1900-48HPv2 switches (firmware up to 2.90(ABTQ.1)C0), to the KEV catalog on September 21, 2026, citing active exploitation. The flaw carries a CVSS v3.1 score of 8.8 and lets an unauthenticated attacker on an adjacent network execute OS commands via a crafted HTTP request to the management interface. Federal agencies must apply mitigations or stop using affected products by September 24 under BOD 26-04, including forensic triage of exposed assets.
- KEV addition September 21 with remediation deadline September 24, 2026
- Unauthenticated adjacent-network attacker can execute OS commands via HTTP
- Affects Zyxel GS1900-48HPv2 firmware up to 2.90(ABTQ.1)C0, CVSS 8.8
- Compromise enables traffic interception, credential theft, and lateral movement
Vulnerabilities mentionedAll →
- CVE-2026-72738.83%Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerabilitypublished · Zyxel GS1900 Series Switches KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article456 words · extracted from gbhackers.com · click to collapse
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included a high-severity vulnerability affecting Zyxel GS1900 Series switches in its Known Exploited Vulnerabilities (KEV) Catalog.
This warning highlights that the flaw, tracked as CVE-2026-7273, has been exploited in the wild. The vulnerability stems from a stack-based buffer overflow in the device’s CGI program.
CISA added this vulnerability on September 21, 2026, and set a deadline of September 24 for affected organizations to either implement vendor mitigations or discontinue using the affected products where mitigations are not available. The agency has classified this issue as requiring forensic triage under Binding Operational Directive (BOD) 26-04.
Flaw in Zyxel GS1900 Switches
CVE-2026-7273 affects Zyxel GS1900-48HPv2 firmware versions up to 2.90(ABTQ.1)C0. According to the CVE record, an unauthenticated attacker on the LAN can exploit the buffer overflow by sending a specially crafted HTTP request, potentially allowing them to execute operating system commands on the switch.
The vulnerability falls under CWE-121 (stack-based buffer overflow) and has a CVSS v3.1 score of 8.8 out of 10. The score’s vector string is: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
This score indicates low attack complexity, lack of required privileges, and the potential for complete compromise of confidentiality, integrity, and availability.
However, the attack vector is an adjacent network, meaning an attacker must reach the vulnerable management interface from the local network or another connected network segment.
Federal civilian executive branch agencies must adhere to CISA’s KEV remediation requirements outlined in BOD 26-04. This directive compels agencies to prioritize remediation based on risk, assess whether vulnerable assets are exposed to the internet, and perform any necessary forensic triage.
Although the KEV entry does not specifically identify ransomware use, the active exploitation of this vulnerability significantly increases the urgency for enterprises and critical infrastructure operators using the affected switches.
Network switches are particularly sensitive targets, as a compromise can lead to traffic interception, management-plane manipulation, credential theft attempts, and lateral movement across connected environments.
Security teams should take the following actions:
- Identify all Zyxel GS1900-48HPv2 devices.
- Verify installed firmware versions.
- Consult Zyxel’s security advisory for vendor-provided remediation guidance.
Recommended Defensive Measures
Organizations should:
- Upgrade affected firmware according to Zyxel’s instructions.
- Restrict switch management interfaces to dedicated administration networks.
- Block HTTP-based management access from untrusted VLANs and user subnets.
- Review device logs, configuration changes, and administrator account activity for signs of compromise.
- Rotate privileged credentials if a vulnerable switch was exposed to untrusted internal networks.
- Segment affected devices until remediation and forensic review are complete.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.