Forwarded from National Information Security Analysis Center Security Information Alert NISAC-200-202610-00000003
[Content Description]
Researchers have discovered a Stack-based Buffer Overflow vulnerability (CVE-2026-7273) in Zyxel GS1900 series switches. An unauthenticated attacker on the same local network can trigger memory corruption by sending specially crafted HTTP requests to the CGI program, thereby executing OS commands on affected devices. The vulnerability has been exploited by hackers. Please confirm and apply patches as soon as possible.
[Affected Platforms]
Zyxel GS1900-10HP versions 2.90(AAZI.1)C0 (inclusive) and earlier
Zyxel GS1900-16 versions 2.90(AAHJ.1)C0 (inclusive) and earlier
Zyxel GS1900-24 versions 2.90(AAHL.1)C0 (inclusive) and earlier
Zyxel GS1900-24E versions 2.90(AAHK.1)C0 (inclusive) and earlier
Zyxel GS1900-24EP versions 2.90(ABTO.1)C0 (inclusive) and earlier
Zyxel GS1900-24HPv2 versions 2.90(ABTP.1)C0 (inclusive) and earlier
Zyxel GS1900-48 versions 2.90(AAHN.1)C0 (inclusive) and earlier
Zyxel GS1900-48HPv2 versions 2.90(ABTQ.1)C0 (inclusive) and earlier
Zyxel GS1900-8 versions 2.90(AAHH.1)C0 (inclusive) and earlier
Zyxel GS1900-8HP versions 2.90(AAHI.1)C0 (inclusive) and earlier
[Recommended Measures]
The vendor has released patches or updates for the vulnerability. Please refer to the official instructions for handling. The URL is as follows: https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026
[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-7273
2. https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026