Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-7273

Zyxel GS1900 Series Switches Stack-Based Buffer Overflow

Stack-based buffer overflow in Zyxel GS1900 CGI program lets unauthenticated LAN attackers execute OS commands. CVSS 8.8, added to CISA KEV September 21, 2026.

cat cve-2026-7273.json
Vendor
Zyxel
Product
GS1900 Series Switches
CVSS
8.8
EPSS (exploit probability)
1.3%
Status
kev
CISA patch-by (BOD 22-01)
Published

CVE-2026-7273 is a stack-based buffer overflow in the CGI program of Zyxel GS1900 series managed switches. A LAN-based, unauthenticated attacker can send a crafted HTTP request to trigger arbitrary OS command execution on the device.

CISA added this vulnerability to its Known Exploited Vulnerabilities catalog on September 21, 2026. Federal Civilian Executive Branch agencies are required to patch by September 24, 2026 under BOD 26-04.

Affected models and patched firmware versions (from Zyxel’s security advisory):

Model Fixed version
GS1900-8 2.90(AAHH.2)C0
GS1900-8HP 2.90(AAHI.2)C0
GS1900-10HP 2.90(AAZI.2)C0
GS1900-16 2.90(AAHJ.2)C0
GS1900-24 2.90(AAHL.2)C0
GS1900-24E 2.90(AAHK.2)C0
GS1900-24EP 2.90(ABTO.2)C0
GS1900-24HPv2 2.90(ABTP.2)C0
GS1900-48 2.90(AAHN.2)C0
GS1900-48HPv2 2.90(ABTQ.2)C0

Update to the patched firmware version for your model. If you cannot patch immediately, restrict management interface access to trusted hosts and monitor for unusual HTTP requests to the switch CGI. See also NVD record for CVE-2026-7273.