Zyxel GS1900 Series Switches Stack-Based Buffer Overflow
Stack-based buffer overflow in Zyxel GS1900 CGI program lets unauthenticated LAN attackers execute OS commands. CVSS 8.8, added to CISA KEV September 21, 2026.
- Vendor
- Zyxel
- Product
- GS1900 Series Switches
- CVSS
- 8.8
- EPSS (exploit probability)
- 1.3%
- Status
- kev
- CISA patch-by (BOD 22-01)
- Published
CVE-2026-7273 is a stack-based buffer overflow in the CGI program of Zyxel GS1900 series managed switches. A LAN-based, unauthenticated attacker can send a crafted HTTP request to trigger arbitrary OS command execution on the device.
CISA added this vulnerability to its Known Exploited Vulnerabilities catalog on September 21, 2026. Federal Civilian Executive Branch agencies are required to patch by September 24, 2026 under BOD 26-04.
Affected models and patched firmware versions (from Zyxel’s security advisory):
| Model | Fixed version |
|---|---|
| GS1900-8 | 2.90(AAHH.2)C0 |
| GS1900-8HP | 2.90(AAHI.2)C0 |
| GS1900-10HP | 2.90(AAZI.2)C0 |
| GS1900-16 | 2.90(AAHJ.2)C0 |
| GS1900-24 | 2.90(AAHL.2)C0 |
| GS1900-24E | 2.90(AAHK.2)C0 |
| GS1900-24EP | 2.90(ABTO.2)C0 |
| GS1900-24HPv2 | 2.90(ABTP.2)C0 |
| GS1900-48 | 2.90(AAHN.2)C0 |
| GS1900-48HPv2 | 2.90(ABTQ.2)C0 |
Update to the patched firmware version for your model. If you cannot patch immediately, restrict management interface access to trusted hosts and monitor for unusual HTTP requests to the switch CGI. See also NVD record for CVE-2026-7273.
