Cve 2026 7273 · Exploits

Zyxel GS1900 switch overflow exploited on 996 devices, now in CISA KEV

Data graphic: Zyxel GS1900 switches exploited. GreyNoise saw 996 switches harvested in 48 countries on or about 17 August, 564 of them with default credentials; the flaw was patched 16 June, added to CISA KEV 21 September, with a KEV due date of 24 September.
MC

Incident response analyst · Updated Oct 2, 2026, 3:25 PM EDT

CISA added Zyxel GS1900 flaw CVE-2026-7273 to KEV on 21 Sept. GreyNoise reports a suspected Chinese-speaking actor took data from 996 switches in 48 countries.

CISA added CVE-2026-7273, a stack-based buffer overflow in the CGI program of Zyxel GS1900 series switches, to its Known Exploited Vulnerabilities (KEV) catalog on 21 September 2026, with a federal remediation due date of 24 September. Zyxel disclosed and patched the flaw on 16 June 2026. Ten GS1900 models are listed as affected, and the advisory documents no workaround, so the firmware update is the only listed fix.

What the vulnerability is

Zyxel describes a stack-based buffer overflow in the CGI program of GS1900 series firmware. An unauthenticated attacker on the local network can send a crafted HTTP request and potentially execute operating system commands. The Zyxel advisory itself gives no score. NVD records a CVSS v3.1 base score of 8.8 (High), vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, and that score comes from Zyxel (security@zyxel.com.tw), listed as a secondary source. NVD shows no score of its own. The weakness is CWE-121.

The "adjacent" attack vector means the attacker must reach the switch's management interface from the same network segment. It does not require credentials or user interaction. Any switch whose management interface is reachable from more networks than intended has a correspondingly larger exposure.

Affected models and fixed firmware

The Zyxel advisory lists ten models. Each is affected through the .1 build and fixed in the .2 build:

ModelAffectedFixed
GS1900-82.90(AAHH.1)C0 and earlier2.90(AAHH.2)C0
GS1900-8HP2.90(AAHI.1)C0 and earlier2.90(AAHI.2)C0
GS1900-10HP2.90(AAZI.1)C0 and earlier2.90(AAZI.2)C0
GS1900-162.90(AAHJ.1)C0 and earlier2.90(AAHJ.2)C0
GS1900-242.90(AAHL.1)C0 and earlier2.90(AAHL.2)C0
GS1900-24E2.90(AAHK.1)C0 and earlier2.90(AAHK.2)C0
GS1900-24EP2.90(ABTO.1)C0 and earlier2.90(ABTO.2)C0
GS1900-24HPv22.90(ABTP.1)C0 and earlier2.90(ABTP.2)C0
GS1900-482.90(AAHN.1)C0 and earlier2.90(AAHN.2)C0
GS1900-48HPv22.90(ABTQ.1)C0 and earlier2.90(ABTQ.2)C0

The NVD description text names only the GS1900-48HPv2, but its structured affected-product data lists the same ten models as the advisory. Zyxel credits Lei Gu, Jun Cao, Zhiqing Rui, Jingzheng Wu and Tianyue Luo of ISCAS with the report.

Exploitation evidence

CISA's KEV entry is the authoritative signal that the flaw is exploited in the wild. It marks known ransomware campaign use as "Unknown" and flags forensic triage as required, and its required action cites CISA's BOD 26-04 guidance.

NVD also carries a CISA SSVC entry dated 17 June 2026 that records exploitation as "active".

Separately, GreyNoise published research on 21 September 2026 about a single malicious actor it describes as a suspected Chinese speaker, possibly working in UTC+8. GreyNoise says the actor is the same as or related to the "Red Heron" activity reported by Acronis, based on shared command-and-control domain, malware family and other tradecraft. That attribution is GreyNoise's assessment. GreyNoise says that on or about 17 August the actor exploited CVE-2026-7273 with a novel exploit and exfiltrated configurations, hashed root-level credentials and networking information from 996 GS1900 switches in 48 countries. GreyNoise wrote that, as of 17 September 2026, this was the first publicly documented exploitation in the wild of the flaw, and that the CVE was not on the KEV catalog at the time of its publication. Of the victims, 564 had factory default credentials.

According to GreyNoise, the exploit was a PyArmor-obfuscated Python script that explicitly targeted GS1900-24 firmware 2.10 through 2.90, with options to adapt to other firmware. On a compromised switch, the exploit ran the TFTP tool to fetch a collector script from attacker infrastructure, then copied the collected output to /home/web/tmp/info.txt. The attribution to this actor is GreyNoise's assessment, not a finding confirmed by Zyxel or CISA.

What defenders should do

  • Inventory every GS1900 switch and compare its firmware against the table above. Install the matching .2 build for your model.
  • Because no workaround is documented, restrict access to the switch's web management interface to a dedicated management VLAN or trusted hosts while patching.
  • Change factory default credentials. GreyNoise reports that 564 of the 996 victims still had factory default credentials.
  • Treat switches that ran an affected build on a reachable segment as potentially compromised. Review configurations for unexpected changes, rotate administrator credentials, and check for unexpected outbound TFTP traffic or unfamiliar files in the web directory.
  • GreyNoise published indicators, including the C2 domain *.981666[.]xyz and the IPs 74.48.66[.]73 (staging), 104.225.153[.]141 (C2) and 172.245.247[.]21 (exploitation). Search logs for them.
  • Federal agencies were due to remediate by 24 September under KEV. That date has passed, so treat any unpatched GS1900 as overdue.

Sources