DIRAS TAKE
Urgent: CISA added this issue to its Known Exploited Vulnerabilities catalog with a rapid remediation deadline, indicating high operational priority; treat internet- or LAN-exposed GS1900 management interfaces as high risk and act immediately.
What is CVE-2026-7273?
A remote unauthenticated attacker on the LAN can trigger a stack-based buffer overflow in the CGI interface of Zyxel GS1900 Series Switches and potentially execute operating-system commands; this is tracked as CVE-2026-7273. The vulnerability affects GS1900 firmware releases up to the listed builds (for example, GS1900-48HPv2 <= 2.90(ABTQ.1)C0 and similar <= 2.90.x builds across GS1900-8, -8HP, -10HP, -16, -24, -24E, -24EP, -24HPv2, and -48 branches). An attacker needs only network access to the device’s management CGI (no authentication or user interaction reported).
Vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Zyxel GS1900 Series Switches are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| GS1900-48HPv2 firmware | <= 2.90(ABTQ.1)C0 | |
| GS1900-8 firmware | <= 2.90(AAHH.1)C0 | |
| GS1900-8HP firmware | <= 2.90(AAHI.1)C0 | |
| GS1900-10HP firmware | <= 2.90(AAZI.1)C0 | |
| GS1900-16 firmware | <= 2.90(AAHJ.1)C0 | |
| GS1900-24 firmware | <= 2.90(AAHL.1)C0 | |
| GS1900-24E firmware | <= 2.90(AAHK.1)C0 | |
| GS1900-24EP firmware | <= 2.90(ABTO.1)C0 | |
| GS1900-24HPv2 firmware | <= 2.90(ABTP.1)C0 | |
| GS1900-48 firmware | <= 2.90(AAHN.1)C0 |
Is CVE-2026-7273 being exploited?
CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-21, and U.S. federal agencies were directed to remediate by 2026-09-24.
How to fix CVE-2026-7273
- Isolate affected GS1900 switches from untrusted networks and block HTTP/management access from the internet and guest VLANs.
- Follow Zyxel’s vendor guidance for mitigations and workarounds; if guidance is unavailable, discontinue use or replace devices where feasible.
- Monitor device logs and network traffic for suspicious CGI requests and signs of command execution or anomalous behavior.
- Restrict management access to a dedicated admin network, apply network-level access controls, and consider disabling the web management interface until mitigations or patches are available.
Frequently asked questions
Is CVE-2026-7273 being actively exploited?
CISA added CVE-2026-7273 to its Known Exploited Vulnerabilities catalog on 2026-09-21, and federal agencies were required to remediate by 2026-09-24.
Which GS1900 Series Switches versions are affected by CVE-2026-7273?
GS1900 Series Switches running firmware at or below the listed builds are affected, for example GS1900-48HPv2 <= 2.90(ABTQ.1)C0 and corresponding <= 2.90.x builds for GS1900-8, -8HP, -10HP, -16, -24, -24E, -24EP, -24HPv2, and -48 branches.
Is there a patch for CVE-2026-7273?
As of 2026-09-29 no fixed firmware versions are listed in the vendor-affected data; apply vendor mitigations or isolate devices until a patch is published.
Does CVE-2026-7273 require authentication?
No; the vulnerability is exploitable by an unauthenticated attacker with network access to the GS1900 CGI management interface.
References
- nvd.nist.gov/vuln/detail/CVE-2026-7273
- cve.org/CVERecord?id=CVE-2026-7273
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-7273
- zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026
- All Zyxel CVEs on CVE Radar
- CVEs published in September 2026