• Request consultation
  • Newsletter
  • Deutsch Deutsch German de
  • English English English en
  • Italiano Italiano Italian it
  • Nederlands Nederlands Dutch nl
Greenbone
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for Your Sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap & Lifecycle
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • MSP GLOBAL 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
  • Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
      • Vulnerability Management
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for your sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap and Lifecycle
    • Request IT Security
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • MSP GLOBAL 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
    • Newsletter
  • Our Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
      • Vulnerability Management
  • German
  • English
  • Italian
  • Dutch
Joseph Lee

CVE-2026-7273: Zyxel GS1900 Switches Actively Exploited Globally

Blog

CVE-2026-7273 (CVSS 8.8, EPSS 1.286% (69th)), published in mid-June 2026, is a stack-based buffer overflow that allows unauthenticated remote code execution (RCE) on Zyxel GS1900 series switches. The flaw is in the device’s firmware CGI program and can be triggered via crafted HTTP request. As of September 21st, 2026, CVE-2026-7273 is considered actively exploited and has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog. According to Zyxel’s advisory, ten GS1900 models are affected. Several national CERT alerts were issued soon after the CVE’s initial disclosure [1][2] and several more have been issued since active exploitation was uncovered [3][4][5].

Critical Zyxel GS1900 switch vulnerability actively exploited worldwide banner

Immediate Action Recommended

Greenbone’s OPENVAS ENTERPRISE FEED added a remote banner check for CVE-2026-7273 immediately after the CVE was published in June 2026. Patches have also been available since the disclosure. Regular vulnerability scanning with OPENVAS SCAN allows defenders to identify and patch affected products before attackers can cause damage. Due to the elevated risk signals, users should upgrade the firmware of their Zyxel GS1900 series switches as soon as possible.

A Risk Assessment of CVE-2026-7273 in Zyxel GS1900 Switches

CVSS 8.8 · HighEPSS 1.3% (69th)Actively exploitedIn CISA KEV

Zyxel GS1900 series switches are smart-managed devices, marketed to small businesses. Their capabilities include VLAN management, Quality of Service (QoS) traffic control, IGMP snooping, Link Aggregation Grouping (LAG), and Denial of Service (DoS) defense.

An attacker with network access to the web interface of a vulnerable switch can exploit CVE-2026-7273 remotely without authentication, privileges, or user interaction by sending a crafted HTTP request to a vulnerable device. Because CVE-2026-7273 allows the execution of OS commands [T1059] on Zyxel GS1900 series switches, an attacker can trigger DoS conditions [T1499.004], or more complex attacks to achieve full arbitrary code execution. Compromise can expose device credentials [T1003] and configuration data [T1602.002], expose traffic on the network to snooping [T1040], and potentially allow data theft [TA0010] or lateral movement [TA0008] to other network devices. This makes the flaw serious for enterprise and small-business environments where administrative interfaces are reachable from internal network segments.

Risk is elevated further by reports of exploitation in the wild. GreyNoise observed attacks targeting CVE-2026-7273 as early as August 17th, and the CVE was added to CISA’s KEV list on September 21st. In total, Zyxel has had 13 entries on CISA’s KEV list since 2021. Two of those entries are associated with ransomware attacks. The GreyNoise report included a technical analysis of the flaw and a reverse-engineering analysis of the Python-based malware payload. However, no fully functional proof-of-concept (PoC) exploits are yet available online.

The Technical Details of CVE-2026-7273

CVE-2026-7273 (CVSS 8.8, EPSS 1.286% (69th)) is a stack-based buffer overflow flaw [CWE-121] in the CGI program of GS1900 series switch firmware. Exploitation happens via memory corruption rather than conventional command injection [CWE-77]. An attacker with network access to the web interface of a vulnerable switch can exploit CVE-2026-7273 remotely without authentication, privileges, or user interaction via specially crafted HTTP request. During request processing, user-supplied data is written to a stack-allocated buffer without adequate bounds checking.

The Python-based exploit analyzed by GreyNoise contains command-line parameters for a libc base address, the address of an object named reqParameters, the Global Offset Table (GOT) entries for strcmp(), and system() within libc. GOT is a data structure used by ELF executables and shared libraries on Linux and other Unix-like systems to resolve addresses that are not known until runtime. The payload’s parameters indicate that the exploit converts a memory-corruption flaw into controlled execution by manipulating dynamically linked function locations. Data that would ordinarily be supplied to strcmp() is redirected to system() to achieve OS command execution on the victim’s computer. However, the GreyNoise analysis doesn’t reveal the full exploit path.

The Campaigns Targeting Zyxel GS1900 Switches

GreyNoise observed that in-the-wild exploitation began on August 17th, 2026. The report described post-compromise data theft from 996 compromised switches across 48 countries. During a successful exploitation, commands were executed via the device’s shell environment. GreyNoise observed the attacker invoking /bin/sh and using the switch’s Trivial File Transfer Protocol (TFTP) client to import a malicious second-stage payload onto the infected device.

Attackers then staged the stolen data in the device’s /home/web/tmp/ directory where it could be retrieved via HTTP request. Attackers exfiltrated hashed root credentials [T1003], configuration data [T1602.002], and networking information from affected devices. GreyNoise also ties exploitation of CVE-2026-7273 to a broader campaign that leveraged software flaws in multiple other technologies including Ubiquiti UniFi OS, WordPress, the Linux kernel, Gitea, Proxmox VE, and PAN-OS GlobalProtect.

Affected Zyxel GS1900 Models and Mitigation for CVE-2026-7273

Immediate Action Recommended

Greenbone’s OPENVAS ENTERPRISE FEED added a remote banner check for CVE-2026-7273 immediately after the CVE was published in June 2026. Patches have also been available since the disclosure. Regular vulnerability scanning with OPENVAS SCAN allows defenders to identify and patch affected products before attackers can cause damage. Due to the elevated risk signals, users should upgrade the firmware of their Zyxel GS1900 series switches as soon as possible.

Zyxel published firmware patches for affected models in a community advisory on June 16th, 2026. No workaround mitigations are available for CVE-2026-7273. Organizations using the affected models should treat the updates as a priority. CISA has also assigned the relatively new forensicTriage flag to CVE-2026-7273 indicating that users should conduct a forensic analysis to determine whether an affected device has already been compromised.

The Zyxel models affected by CVE-2026-7273 are listed below:

Model Affected versions Fixed versions

GS1900-8

2.90(AAHH.1)C0 and earlier

2.90(AAHH.2)C0

GS1900-8HP

2.90(AAHI.1)C0 and earlier

2.90(AAHI.2)C0

GS1900-10HP

2.90(AAZI.1)C0 and earlier

2.90(AAZI.2)C0

GS1900-16

2.90(AAHJ.1)C0 and earlier

2.90(AAHJ.2)C0

GS1900-24

2.90(AAHL.1)C0 and earlier

2.90(AAHL.2)C0

GS1900-24E

2.90(AAHK.1)C0 and earlier

2.90(AAHK.2)C0

GS1900-24EP

2.90(ABTO.1)C0 and earlier

2.90(ABTO.2)C0

GS1900-24HPv2

2.90(ABTP.1)C0 and earlier

2.90(ABTP.2)C0

GS1900-48

2.90(AAHN.1)C0 and earlier

2.90(AAHN.2)C0

GS1900-48HPv2

2.90(ABTQ.1)C0 and earlier

2.90(ABTQ.2)C0

Summary

CVE-2026-7273 is a high-severity stack-based buffer overflow in the CGI program of Zyxel GS1900 series switch firmware that can be exploited by an unauthenticated attacker with network access to the devices. Exploitation allows OS command execution on the device. The flaw has been exploited in the wild, and some technical details for exploitation have been published. In the observed campaign, attackers focused on data exfiltration from breached devices.

Immediate Action Recommended

Greenbone’s OPENVAS ENTERPRISE FEED added a remote banner check for CVE-2026-7273 immediately after the CVE was published in June 2026. Patches have also been available since the disclosure. Regular vulnerability scanning with OPENVAS SCAN allows defenders to identify and patch affected products before attackers can cause damage. Due to the elevated risk signals, users should upgrade the firmware of their Zyxel GS1900 series switches as soon as possible.

 

Contact Test Now Buy Here Back to Overview
Joseph Lee
Joseph Lee

Joseph has had a varied and passionate background in IT and cyber security since the late 1980s. His early technical experience included working on an IBM PS/2, assembling PCs and programming in C++.

He also pursued academic studies in computer and systems engineering, anthropology and an MBA in technology forecasting.

Joseph has worked in data analytics, software development and, in particular, enterprise IT security. He specialises in vulnerability management, encryption and penetration testing.

LinkedIn

28. September 2026/by Joseph Lee
Share this entry
  • Share on LinkedIn
  • Share by Mail
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-09-28 13:23:052026-09-28 13:49:48CVE-2026-7273: Zyxel GS1900 Switches Actively Exploited Globally

Search

Search Search

Archive

  • 2026
  • 2025

Newsletter

Subscribe Now

OPENVAS BASIC

Our entry-level enterprise product

Test 14 Days Free of Charge

Products & Solutions

  • OPENVAS PRODUCTS
  • OPENVAS SECURITY INTELLIGENCE
  • OPENVAS SCAN
  • OPENVAS BASIC
  • OPENVAS FREE
  • OPENVAS AI
ISO9001-EN

Service & Support

  • Professional Services
  • Documents
  • Technical Support
  • FAQ
  • Warranty
  • Cyber Resilience Act
ISO27001-EN

About us

  • About Greenbone
  • Partners
  • MSSP
  • License information
  • Privacy Statement
  • Terms & Conditions
ISO14001-EN

Contact with us

  • Contact
  • Newsletter
  • Media Contact
  • Careers
  • Security Response
  • Imprint
  • Grounding Page

Community

  • Community Portal
  • Community Forum
© Copyright - Greenbone AG 2020-2026
  • Link to LinkedIn
Link to: CVE-2026-48842: Unauthenticated SQL Injection Flaw in Roundcube Webmail Now Targeted Link to: CVE-2026-48842: Unauthenticated SQL Injection Flaw in Roundcube Webmail Now Targeted CVE-2026-48842: Unauthenticated SQL Injection Flaw in Roundcube Webmail Now...
Scroll to top Scroll to top Scroll to top
Contact
Request IT Security Contact Us Subscribe to Newsletter Follow on LinkedIn