CISA Flags Zyxel GS1900 Switch Flaw CVE-2026-7273 as Actively Exploited
A critical stack-based buffer overflow vulnerability, CVE-2026-7273, affects multiple Zyxel GS1900 series managed switches, allowing an unauthenticated attacker on the local network to execute arbitrary OS commands via a crafted HTTP request to the web management interface. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 21, 2026, confirming active exploitation in the wild. Scored 8.8 out of 10 under CVSS 3.1, the vulnerability gives attackers control over VLAN configurations, port mirroring, routing, and stored credentials, effectively dismantling network segmentation. Ten GS1900 models running firmware version 2.90(x.1)C0 or earlier are affected, with Zyxel having released patched firmware (2.90(x.2)C0) for each. Administrators are urged to apply the fixed firmware immediately using download links provided in Zyxel's official security advisory.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.



Discussion (0)
Log in to join the discussion and vote.
Log in