CISA Warns of Active Exploitation of Zyxel GS1900 Switch Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity vulnerability in Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) Catalog, warning that attackers are actively exploiting the flaw.
CVE-2026-7273 allows remote command execution on LANs
Tracked as CVE-2026-7273, the vulnerability is a stack-based buffer overflow in a CGI program. An unprivileged attacker with access to the local area network (LAN) can exploit the flaw by sending a specially crafted HTTP request to execute operating system commands.
Zyxel released a security update for the vulnerability on June 16 and advised customers to upgrade their firmware “for optimal protection.”
Zyxel has not yet updated its advisory to confirm active exploitation. However, CISA added CVE-2026-7273 to the KEV Catalog on Monday.
Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies must identify the affected switches and protect them from ongoing attacks by Thursday.
“These types of vulnerabilities are a frequent attack vector for malicious cyber attackers and pose significant risks to federal enterprises,” CISA said.
CISA added that although BOD 26-04 applies only to FCEB institutions, it encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of vulnerabilities listed in the KEV Catalog.
Affected Zyxel GS1900 switch models and firmware versions
| Affected models | Affected versions | Patch availability |
|---|---|---|
| GS1900-8 | 2.90(AAHH.1)C0 or earlier | 2.90(AAHH.2)C0 |
| GS1900-8HP | 2.90(AAHI.1)C0 or earlier | 2.90(AAHI.2)C0 |
| GS1900-10HP | 2.90(AAZI.1)C0 or earlier | 2.90(AAZI.2)C0 |
| GS1900-16 | 2.90(AAHJ.1)C0 or earlier | 2.90(AAHJ.2)C0 |
| GS1900-24 | 2.90(AAHL.1)C0 or earlier | 2.90(AAHL.2)C0 |
| GS1900-24E | 2.90(AAHK.1)C0 or earlier | 2.90(AAHK.2)C0 |
| GS1900-24EP | 2.90(ABTO.1)C0 or earlier | 2.90(ABTO.2)C0 |
| GS1900-24HPv2 | 2.90(ABTP.1)C0 or earlier | 2.90(ABTP.2)C0 |
| GS1900-48 | 2.90(AAHN.1)C0 or earlier | 2.90(AAHN.2)C0 |
| GS1900-48HPv2 | 2.90(ABTQ.1)C0 or earlier | 2.90(ABTQ.2)C0 |
GreyNoise reports nearly 1,000 compromised switches
CISA has not released technical details about the attacks exploiting CVE-2026-7273. However, threat intelligence company GreyNoise reported that it detected the first signs of exploitation last Thursday.
According to GreyNoise, a Chinese-speaking malicious cyber attacker (MCA) has compromised approximately 1,000 Zyxel GS1900 switches as part of a broader campaign targeting more than a dozen vulnerabilities in various software and technology products.
“GreyNoise has discovered that MCA is targeting ZyXEL GS1900 smart managed switches globally with a new exploit for CVE-2026-7273. As of September 17, 2026, this is the first publicly documented exploitation of this vulnerability,” the company said.
GreyNoise said the attacker successfully exploited the flaw and exfiltrated sensitive data from 996 Zyxel switches across 48 countries.
Zyxel devices remain a frequent target
Zyxel devices are frequently targeted because internet service providers in many countries provide them as default equipment with new internet service contracts.
In February, Zyxel warned that it did not plan to patch two actively exploited zero-day bugs, listed as CVE-2024-40891 and CVE-2024-40891, affecting end-of-life routers that are still being sold online. Instead, the company strongly advised customers to replace those routers with newer products containing patched firmware.
CISA is currently tracking 13 Zyxel vulnerabilities in its KEV Catalog. The vulnerabilities affect Zyxel routers, switches, firewalls, and network-attached storage devices that have been or are currently being exploited.
Zyxel says more than 1 million businesses in 150 markets worldwide use its networking solutions.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



