Vulnerability
Published 2026-09-21
Verified 2026-09-22

Zyxel GS1900 stack buffer overflow CVE-2026-7273 (CVSS 8.8); CISA KEV 21 Sep

CISA added CVE-2026-7273 to the Known Exploited Vulnerabilities catalog on 21 September 2026 (catalogVersion 2026.09.21; FCEB due 24 September 2026; forensic triage required under BOD 26-04). Zyxel’s security advisory (16 June 2026) documents a stack-based buffer overflow (CWE-121) in the CGI program of GS1900 series switch firmware: a LAN-based, unauthenticated attacker can send a crafted HTTP request and potentially execute OS commands. NVD (Zyxel as CVSS source) scores CVSS 3.1 8.8 High (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H); NVD description cites GS1900-48HPv2 firmware through 2.90(ABTQ.1)C0. Vendor patch table maps each GS1900 SKU from 2.90(.*).1)C0 and earlier to fixed 2.90(.*).2)C0 builds (e.g. GS1900-48HPv2 → 2.90(ABTQ.2)C0; GS1900-8 → 2.90(AAHH.2)C0). Known ransomware campaign use: Unknown per CISA. Australia relevance: GS1900 is a common SMB/managed-access switch line — patch LAN-management exposure.

Product
Zyxel GS1900 series switches (CGI / web management)
Versions
Affected: GS1900-8/8HP/10HP/16/24/24E/24EP/24HPv2/48/48HPv2 firmware 2.90(.*).1)C0 and earlier (NVD example GS1900-48HPv2 through 2.90(ABTQ.1)C0). Fixed: corresponding 2.90(.*).2)C0 builds per Zyxel table (e.g. 2.90(ABTQ.2)C0 / 2.90(AAHH.2)C0)
CVSS
(CVSS 3.1 High; Zyxel via NVD)
Exploited in Australia?
unknown
Patch to
Install Zyxel GS1900 2.90(.*).2)C0 firmware for your SKU from the 16 Jun 2026 advisory; restrict switch web/CGI management to trusted LAN admin segments; meet CISA BOD 26-04 FCEB due 2026-09-24 and forensic-triage requirements for internet-exposed assets

Primary: Zyxel — GS1900 stack buffer overflow advisory CVE-2026-7273 (16 Jun 2026) · Vendor: Zyxel security advisory — GS1900 series patch table · CVE: CVE-2026-7273 · CISA KEV — CVE-2026-7273 added 21 Sep 2026 (due 24 Sep; BOD 26-04); NVD detail

vulnerabilities network