CVE-2026-7273
published 2026-06-16CVE-2026-7273: A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based…
PriorityP188high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-09-24
Exploited in the wild
EPSS
2.50%
84.2th percentile
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | gs1900-10hp_firmware | < 2.90\(aazi.2\)c0 | 2.90\(aazi.2\)c0 |
| zyxel | gs1900-10hp_firmware | <= 2.90(AAZI.1)C0 | — |
| zyxel | gs1900-16_firmware | < 2.90\(aahj.2\)c0 | 2.90\(aahj.2\)c0 |
| zyxel | gs1900-16_firmware | <= 2.90(AAHJ.1)C0 | — |
| zyxel | gs1900-24_firmware | < 2.90\(aahl.2\)c0 | 2.90\(aahl.2\)c0 |
| zyxel | gs1900-24_firmware | <= 2.90(AAHL.1)C0 | — |
| zyxel | gs1900-24e_firmware | < 2.90\(aahk.2\)c0 | 2.90\(aahk.2\)c0 |
| zyxel | gs1900-24e_firmware | <= 2.90(AAHK.1)C0 | — |
| zyxel | gs1900-24ep_firmware | < 2.90\(abto.2\)c0 | 2.90\(abto.2\)c0 |
| zyxel | gs1900-24ep_firmware | <= 2.90(ABTO.1)C0 | — |
| zyxel | gs1900-24hpv2_firmware | < 2.90\(abtp.2\)c0 | 2.90\(abtp.2\)c0 |
| zyxel | gs1900-24hpv2_firmware | <= 2.90(ABTP.1)C0 | — |
| zyxel | gs1900-48_firmware | < 2.90\(aahn.2\)c0 | 2.90\(aahn.2\)c0 |
| zyxel | gs1900-48_firmware | <= 2.90(AAHN.1)C0 | — |
| zyxel | gs1900-48hpv2_firmware | < 2.90\(abtq.2\)c0 | 2.90\(abtq.2\)c0 |
| zyxel | gs1900-48hpv2_firmware | <= 2.90(ABTQ.1)C0 | — |
| zyxel | gs1900-8_firmware | < 2.90\(aahh.2\)c0 | 2.90\(aahh.2\)c0 |
| zyxel | gs1900-8_firmware | <= 2.90(AAHH.1)C0 | — |
| zyxel | gs1900-8hp_firmware | < 2.90\(aahi.2\)c0 | 2.90\(aahi.2\)c0 |
| zyxel | gs1900-8hp_firmware | <= 2.90(AAHI.1)C0 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
cisa·2026-09-21·CVSS 8.8
CVE-2026-7273 [HIGH] CWE-121 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
Vulnerability: Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
Affected: Zyxel GS1900 Series Switches
Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's in
VulDB
Zyxel GS1900-48 up to 2.90(ABTQ.1)C0 HTTP stack-based overflow (EUVD-2026-37030)
vuldb·2026-09-22·CVSS 8.8
CVE-2026-7273 [HIGH] Zyxel GS1900-48 up to 2.90(ABTQ.1)C0 HTTP stack-based overflow (EUVD-2026-37030)
A vulnerability categorized as critical has been discovered in Zyxel GS1900-48HPv2, GS1900-8, GS1900-8HP, GS1900-10HP, GS1900-16, GS1900-24, GS1900-24E, GS1900-24EP, GS1900-24HPv2 and GS1900-48 up to 2.90(ABTQ.1)C0. This affects an unknown function of the component HTTP Handler. Such manipulation leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2026-7273. Access to the local network is required for this attack to succeed. Furthermore, there is an exploit available.
GHSA
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and
ghsa_unreviewed·2026-06-16
CVE-2026-7273 [HIGH] CWE-121 A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
VulnCheck
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
vulncheck·2026·CVSS 8.8
CVE-2026-7273 [HIGH] CWE-121 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
Affected: Zyxel GS1900 Series Switches
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposur
No detection rules found.
No public exploits indexed.
Hackernews
Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
blogs_hackernews·2026-09-22·CVSS 8.8
CVE-2026-7273 [HIGH] Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities ( KEV ) catalog, citing evidence of active exploitation.
The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating system (OS) command execution.
"A stack-based buffer overflow vulnerability in the CGI program of the Zyxel GS1900 series switch firmware could allow a LAN-b
Greynoiseio
Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation
blogs_greynoiseio·2026-09-21
CVE-2026-7273 Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation
GreyNoise observes adversary activity through our Global Observation Grid (GOG), a network of sensors that draws attacker scanning and exploitation onto infrastructure we control. This lets us study adversary infrastructure, tooling, and tradecraft directly, without waiting for a victim investigation. GreyNoise has been tracking malicious use of an IP address since early June 2026 due to its frequent use in scans and attacks against a variety of technologies. We are withholding the exact IP address due to victim sensitivities and operational risk. Once these factors have been mitigated, GreyNoise will publish an update.
While numerous adversaries have commonalities, adversary behavior is not monolithic. One security opinion is that adversaries rotate through IP addresses such that blockin
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-7273https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitation
2026-06-16
Published
2026-09-21
Added to CISA KEV
Exploited in the wild