CVE-2026-7273
published 2026-06-16CVE-2026-7273: A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based…
PriorityP358high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.32%
23.9th percentile
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | gs1900-10hp_firmware | <= 2.90(AAZI.1)C0 | — |
| zyxel | gs1900-16_firmware | <= 2.90(AAHJ.1)C0 | — |
| zyxel | gs1900-24_firmware | <= 2.90(AAHL.1)C0 | — |
| zyxel | gs1900-24e_firmware | <= 2.90(AAHK.1)C0 | — |
| zyxel | gs1900-24ep_firmware | <= 2.90(ABTO.1)C0 | — |
| zyxel | gs1900-24hpv2_firmware | <= 2.90(ABTP.1)C0 | — |
| zyxel | gs1900-48_firmware | <= 2.90(AAHN.1)C0 | — |
| zyxel | gs1900-48hpv2_firmware | <= 2.90(ABTQ.1)C0 | — |
| zyxel | gs1900-8_firmware | <= 2.90(AAHH.1)C0 | — |
| zyxel | gs1900-8hp_firmware | <= 2.90(AAHI.1)C0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-16
Published