Your access switch just got a three-day federal clock. CISA added a Zyxel GS1900 stack overflow to KEV on September 21 with a September 24 due date — and the bug needs no login from the LAN.
What happened
On June 16, 2026, Zyxel disclosed a stack-based buffer overflow in the CGI program on GS1900-series switch firmware. A LAN-based, unauthenticated attacker can send a crafted HTTP request and potentially execute OS commands on the switch.
On September 21, 2026, CISA added CVE-2026-7273 to the Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. Federal Civilian Executive Branch agencies must remediate by September 24, 2026, with forensic triage required under BOD 26-04.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Affected models span the GS1900 family still in vulnerability support (8 through 48-port, including PoE variants). Patched firmware is the corresponding 2.90(.2)C0 build for each SKU.
Why it matters
Access switches are not “just Layer 2.” Compromise means VLAN pivots, DHCP/DNS poisoning positions, credential sniffing on mis-segmented management, and a lasting foothold that survives workstation reimages. Unauth + LAN-reachable management CGI is the classic campus/branch blast radius: one guest VLAN leak or compromised laptop becomes switch root.
The advisory is months old; the KEV add is new. Treat every unpatched GS1900 as pre-compromised until firmware and forensics say otherwise.
What to do first
- Inventory every GS1900 (and lookalikes still on 2.90(.1)C0 or earlier). Pull serial/model/firmware from NMS or a site walk.
- Upgrade each listed model to its 2.90(.2)C0 build from Zyxel’s advisory table.
- Restrict management HTTP/HTTPS to a dedicated management VLAN/ACL — never from user or guest VLANs.
- After patch: forensic triage per BOD 26-04 — review switch config diffs, unexpected admin accounts, anomalous VLAN/SPAN/mirror sessions, and upstream firewall logs for management-plane oddities in the pre-patch window.
- If compromise is likely: preserve config forensics, factory-reset or re-image with fixed firmware, re-apply known-good config, and rotate any credentials/SNMP communities/certs that lived on the box.
Details
- CVE: CVE-2026-7273 (CVSS 8.8 — AV:A/AC:L/PR:N/UI:N)
- CWE: CWE-121 Stack-based Buffer Overflow
- Product: Zyxel GS1900 series switches (models in advisory table)
- KEV: Added 2026-09-21; federal due 2026-09-24; forensic triage Yes
- Ransomware use (CISA): Unknown
- Attack vector: Adjacent/LAN, unauthenticated HTTP to CGI
| Model | Affected | Fixed |
|---|---|---|
| GS1900-8 | ≤ 2.90(AAHH.1)C0 | 2.90(AAHH.2)C0 |
| GS1900-8HP | ≤ 2.90(AAHI.1)C0 | 2.90(AAHI.2)C0 |
| GS1900-10HP | ≤ 2.90(AAZI.1)C0 | 2.90(AAZI.2)C0 |
| GS1900-16 | ≤ 2.90(AAHJ.1)C0 | 2.90(AAHJ.2)C0 |
| GS1900-24 | ≤ 2.90(AAHL.1)C0 | 2.90(AAHL.2)C0 |
| GS1900-24E | ≤ 2.90(AAHK.1)C0 | 2.90(AAHK.2)C0 |
| GS1900-24EP | ≤ 2.90(ABTO.1)C0 | 2.90(ABTO.2)C0 |
| GS1900-24HPv2 | ≤ 2.90(ABTP.1)C0 | 2.90(ABTP.2)C0 |
| GS1900-48 | ≤ 2.90(AAHN.1)C0 | 2.90(AAHN.2)C0 |
| GS1900-48HPv2 | ≤ 2.90(ABTQ.1)C0 | 2.90(ABTQ.2)C0 |
Hunt / verify
- Confirm running firmware equals the matching
.2)C0build — not “updates applied.” - Diff running config against last known-good; flag new users, SNMP changes, mirror/SPAN, ACL holes.
- Search management-plane logs and upstream firewalls for anomalous POSTs to switch CGI before the patch window.
- Re-check that management interfaces are not reachable from user/guest VLANs.
Sources
- https://www.cisa.gov/news-events/alerts/2026/09/21/cisa-adds-one-known-exploited-vulnerability-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026
- https://nvd.nist.gov/vuln/detail/CVE-2026-7273
- https://www.cve.org/CVERecord?id=CVE-2026-7273
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.