CVE-2026-7273: Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

Summary

A stack-based buffer overflow vulnerability has been identified in Zyxel GS1900 Series Switches. This flaw, present in the CGI program, could permit an unauthenticated attacker on the local area network to execute arbitrary OS commands by sending a specially crafted HTTP request. Organizations are advised to implement vendor-provided mitigations and adhere to CISA's guidance on prioritizing security updates.

IFF Assessment

FOE

The discovery of a buffer overflow vulnerability that allows for arbitrary command execution poses a significant risk to network infrastructure, enabling attackers to compromise systems.

Severity

8.8 High

CISA KEV: Listed as actively exploited. Federal patch due: September 24, 2026. Known ransomware use: Unknown.

Defender Context

This vulnerability in Zyxel GS1900 series switches highlights the ongoing risk of critical flaws in network infrastructure devices. Defenders should prioritize patching or mitigating this vulnerability to prevent potential command execution by unauthenticated attackers on their LANs. Keeping an inventory of network devices and their firmware versions is crucial for timely patching.

Read Full Story →