Zyxel GS1900 CVE-2026-7273: Unauth LAN Stack Overflow to OS Commands — KEV Due September 24

By George Bailey   Published: 09/21/26   Updated: 09/21/26   3 min read

Your access switch just got a three-day federal clock. CISA added a Zyxel GS1900 stack overflow to KEV on September 21 with a September 24 due date — and the bug needs no login from the LAN.

What happened

On June 16, 2026, Zyxel disclosed a stack-based buffer overflow in the CGI program on GS1900-series switch firmware. A LAN-based, unauthenticated attacker can send a crafted HTTP request and potentially execute OS commands on the switch.

On September 21, 2026, CISA added CVE-2026-7273 to the Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. Federal Civilian Executive Branch agencies must remediate by September 24, 2026, with forensic triage required under BOD 26-04.

Affected models span the GS1900 family still in vulnerability support (8 through 48-port, including PoE variants). Patched firmware is the corresponding 2.90(.2)C0 build for each SKU.

Why it matters

Access switches are not “just Layer 2.” Compromise means VLAN pivots, DHCP/DNS poisoning positions, credential sniffing on mis-segmented management, and a lasting foothold that survives workstation reimages. Unauth + LAN-reachable management CGI is the classic campus/branch blast radius: one guest VLAN leak or compromised laptop becomes switch root.

The advisory is months old; the KEV add is new. Treat every unpatched GS1900 as pre-compromised until firmware and forensics say otherwise.

What to do first

Details

ModelAffectedFixed
GS1900-8≤ 2.90(AAHH.1)C02.90(AAHH.2)C0
GS1900-8HP≤ 2.90(AAHI.1)C02.90(AAHI.2)C0
GS1900-10HP≤ 2.90(AAZI.1)C02.90(AAZI.2)C0
GS1900-16≤ 2.90(AAHJ.1)C02.90(AAHJ.2)C0
GS1900-24≤ 2.90(AAHL.1)C02.90(AAHL.2)C0
GS1900-24E≤ 2.90(AAHK.1)C02.90(AAHK.2)C0
GS1900-24EP≤ 2.90(ABTO.1)C02.90(ABTO.2)C0
GS1900-24HPv2≤ 2.90(ABTP.1)C02.90(ABTP.2)C0
GS1900-48≤ 2.90(AAHN.1)C02.90(AAHN.2)C0
GS1900-48HPv2≤ 2.90(ABTQ.1)C02.90(ABTQ.2)C0

Hunt / verify

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.