Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
🚨SEVERITY: HIGH — CVSS 8.8Security Advisory
TL;DR 📌
- Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
- Highest CVSS: 8.8 (High).
- Listed in CISA KEV (2026-09-21) — this is being exploited in the wild.
- Fixed in
2.90\(aahh.2\)c0,2.90\(aahi.2\)c0,2.90\(aahj.2\)c0,2.90\(aahk.2\)c0— upgrade to this release or later. - CVEs: CVE-2026-7273.
What it is
Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
For leadership ðŸ§
Executive summary. Risk is High (CVSS 8.8) across any Zyxel kit you run. Follow the remediation in the vendor advisory within Immediate — CISA KEV entries carry a federal remediation deadline.
Why it matters:
- Exposure depends on deployment topology and which access paths reach the affected component.
- Treat internet-facing and management-plane instances as higher risk than internal-only ones.
- Keep monitoring for abnormal authentication and configuration events until upgrades complete.
Now / Next / Later:
- Now: confirm whether you run the affected versions, and check exposure of any that are internet-facing.
- Next: apply the remediation the advisory specifies, through an approved change window.
- Later: add a control check so builds cannot drift back onto a vulnerable train.