Posting Date: 2026/10/05
【Vulnerability Alert】High-Risk Security Vulnerability in Zyxel GS1900 Series Switches (CVE-2026-7273), Please Verify and Patch Promptly
- Subject:【Vulnerability Alert】High-Risk Security Vulnerability in Zyxel GS1900 Series Switches (CVE-2026-7273), Please Verify and Patch Promptly
- Description:
- Forwarded NISAC Cybersecurity Message Alert NISAC-200-202610-00000003
- Researchers have discovered a stack-based buffer overflow vulnerability (CVE-2026-7273) in Zyxel GS1900 series switches. An unauthenticated LAN attacker may trigger memory corruption by sending a specially crafted HTTP request to the CGI program, thereby executing operating system commands on affected devices. This vulnerability has already been exploited by attackers. Please verify and patch promptly.
- Affected Platforms:
- Zyxel GS1900-10HP version 2.90(AAZI.1)C0 and earlier
- Zyxel GS1900-16 version 2.90(AAHJ.1)C0 and earlier
- Zyxel GS1900-24 version 2.90(AAHL.1)C0 and earlier
- Zyxel GS1900-24E version 2.90(AAHK.1)C0 and earlier
- Zyxel GS1900-24EP version 2.90(ABTO.1)C0 and earlier
- Zyxel GS1900-24HPv2 version 2.90(ABTP.1)C0 and earlier
- Zyxel GS1900-48 version 2.90(AAHN.1)C0 and earlier
- Zyxel GS1900-48HPv2 version 2.90(ABTQ.1)C0 and earlier
- Zyxel GS1900-8 version 2.90(AAHH.1)C0 and earlier
- Zyxel GS1900-8HP version 2.90(AAHI.1)C0 and earlier
- Recommended Actions:
- The vendor has released a patch or update for the vulnerability, please refer to the vendor's instructions for remediation; URL is as follows: https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026
- References:
Computer and Communication Center
Network System Division