• CISA KEV
  • EXPLOITED

CVE-2026-7273: pre-auth remote code execution in Zyxel GS1900 Series Switches

A remote unauthenticated attacker on the LAN can trigger a stack-based buffer overflow in the CGI interface of Zyxel GS1900 Series Switches and potentially execute operating-system commands; this is tracked as CVE-2026-7273. The vulnerability affects GS1900 firmware releases up to the listed builds (for example, GS1900-48HPv2 <= 2.90(ABTQ.1)C0 and similar <= 2.90.x builds across GS1900-8, -8HP, -10HP, -16, -24, -24E, -24EP, -24HPv2, and -48 branches). An attacker needs only network access to the device’s management CGI (no authentication or user interaction reported).

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
8.8HIGH
EPSS
0.02501
CWE
CWE-121
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent: CISA added this issue to its Known Exploited Vulnerabilities catalog with a rapid remediation deadline, indicating high operational priority; treat internet- or LAN-exposed GS1900 management interfaces as high risk and act immediately.

What is CVE-2026-7273?

A remote unauthenticated attacker on the LAN can trigger a stack-based buffer overflow in the CGI interface of Zyxel GS1900 Series Switches and potentially execute operating-system commands; this is tracked as CVE-2026-7273. The vulnerability affects GS1900 firmware releases up to the listed builds (for example, GS1900-48HPv2 <= 2.90(ABTQ.1)C0 and similar <= 2.90.x builds across GS1900-8, -8HP, -10HP, -16, -24, -24E, -24EP, -24HPv2, and -48 branches). An attacker needs only network access to the device’s management CGI (no authentication or user interaction reported).

Vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Zyxel GS1900 Series Switches are affected?

BRANCHAFFECTEDFIXED
GS1900-48HPv2 firmware<= 2.90(ABTQ.1)C0
GS1900-8 firmware<= 2.90(AAHH.1)C0
GS1900-8HP firmware<= 2.90(AAHI.1)C0
GS1900-10HP firmware<= 2.90(AAZI.1)C0
GS1900-16 firmware<= 2.90(AAHJ.1)C0
GS1900-24 firmware<= 2.90(AAHL.1)C0
GS1900-24E firmware<= 2.90(AAHK.1)C0
GS1900-24EP firmware<= 2.90(ABTO.1)C0
GS1900-24HPv2 firmware<= 2.90(ABTP.1)C0
GS1900-48 firmware<= 2.90(AAHN.1)C0

Is CVE-2026-7273 being exploited?

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-21, and U.S. federal agencies were directed to remediate by 2026-09-24.

How to fix CVE-2026-7273

  1. Isolate affected GS1900 switches from untrusted networks and block HTTP/management access from the internet and guest VLANs.
  2. Follow Zyxel’s vendor guidance for mitigations and workarounds; if guidance is unavailable, discontinue use or replace devices where feasible.
  3. Monitor device logs and network traffic for suspicious CGI requests and signs of command execution or anomalous behavior.
  4. Restrict management access to a dedicated admin network, apply network-level access controls, and consider disabling the web management interface until mitigations or patches are available.

Frequently asked questions

Is CVE-2026-7273 being actively exploited?

CISA added CVE-2026-7273 to its Known Exploited Vulnerabilities catalog on 2026-09-21, and federal agencies were required to remediate by 2026-09-24.

Which GS1900 Series Switches versions are affected by CVE-2026-7273?

GS1900 Series Switches running firmware at or below the listed builds are affected, for example GS1900-48HPv2 <= 2.90(ABTQ.1)C0 and corresponding <= 2.90.x builds for GS1900-8, -8HP, -10HP, -16, -24, -24E, -24EP, -24HPv2, and -48 branches.

Is there a patch for CVE-2026-7273?

As of 2026-09-29 no fixed firmware versions are listed in the vendor-affected data; apply vendor mitigations or isolate devices until a patch is published.

Does CVE-2026-7273 require authentication?

No; the vulnerability is exploitable by an unauthenticated attacker with network access to the GS1900 CGI management interface.

References