Zyxel GS1900 Switches Under Active Attack

Red | Vulnerability
Zyxel GS1900 Switches Under Active Attack | HiveForce Labs Threat Advisory
HiveForce Labs · Threat Advisory · Vulnerability Report

Zyxel GS1900 Switches Under Active Attack

CVE-2026-7273, a stack-based buffer overflow in the Zyxel GS1900 CGI web management component, lets an unauthenticated LAN attacker run operating-system commands. A threat actor has already compromised and stolen data from 996 GS1900 switches across 48 countries.

Threat Level: RedVulnerability ReportTA2026277Published September 23, 2026Admiralty A1
TA Number
TA2026277
Published
September 23, 2026
Admiralty Code
A1
Threat Level
Red
Report Type
Vulnerability Report
First Seen
June 2026
CVE
CVE-2026-7273
CWE
CWE-121
Compromised
996 switches, 48 countries

01 / Overview

Summary

CVE-2026-7273 is a stack-based buffer overflow in the CGI (web management) component of Zyxel GS1900 series smart managed switches. A LAN-based attacker who has not logged in can send a specially crafted HTTP request to the device and run operating-system commands on it.

Zyxel released fixed firmware in June 2026, but a threat actor began exploiting Zyxel GS1900 switches that had not been patched, with activity tied to CVE-2026-7273 starting on or about August 17, 2026. The actor compromised and stole data from 996 GS1900 switches across 48 countries. Patched firmware is available, so organizations running affected Zyxel GS1900 switches should update to the fixed version immediately and check their devices for signs of compromise.

Affected Products
GS1900-8GS1900-8HPGS1900-10HPGS1900-16GS1900-24GS1900-24EGS1900-24EPGS1900-24HPv2GS1900-48GS1900-48HPv2
CVE
CVENameAffected ProductZero-DayCISA KEVPatch
CVE-2026-7273Zyxel GS1900 Series Switches Stack-Based Buffer Overflow VulnerabilityZyxel GS1900 Series SwitchesNoYesAvailable

02 / Technical Analysis

Vulnerability Details

  1. #01

    CVE-2026-7273 is a stack-based buffer overflow (CWE-121) in the CGI program that powers the web management interface of Zyxel GS1900 series switch firmware. A buffer overflow happens when a program accepts more input than the memory space it set aside can hold, so the extra data spills into adjacent memory. When an attacker controls that overflow, they can corrupt how the program runs and ultimately steer it into executing their own commands.

  2. #02

    Exploitation needs no credentials. An attacker on the same local network sends a crafted HTTP request to the Zyxel GS1900 management interface, and a successful request lets them execute operating-system commands on the device. Because the flaw is reached before any login, and the switch is a trusted piece of network plumbing, a single request can turn a managed switch into an attacker-controlled one.

  3. #03

    The vulnerability affects GS1900 firmware version 2.90(XXXX.1)C0 and earlier across ten models, and Zyxel published patched firmware for the supported models on June 16, 2026. The exploit observed in the wild was written specifically for firmware 2.10 through 2.90 of the GS1900-24. Still, it included options that let the attacker adapt it to other affected models and firmware, so every unpatched GS1900 in scope should be treated as at risk.

  4. #04

    The actor carried out the exploitation using a Python script hidden with the commercial obfuscation tool PyArmor (a legacy 6.7.5 runtime was left in place, which aided analysis). After breaking into a switch, the actor used the exploit to fetch a small custom collector script over TFTP from its own infrastructure, ran it to gather the device's configuration, hashed root credentials, and network details, and staged that data on the device for retrieval.

  5. #05

    GreyNoise reported that 996 switches across 48 countries were compromised, led by Italy, the United States, Taiwan, France, and South Korea, and that 564 of them were still using factory-default credentials. The takeaway is straightforward: Zyxel's patched firmware closes CVE-2026-7273, so any GS1900 switch still on a vulnerable version should be updated without delay.

Vulnerability
CVE IDAffected ProductsAffected CPECWE ID
CVE-2026-7273Zyxel GS1900-8 (Before 2.90(AAHH.2)C0), GS1900-8HP (Before 2.90(AAHI.2)C0), GS1900-10HP (Before 2.90(AAZI.2)C0), GS1900-16 (Before 2.90(AAHJ.2)C0), GS1900-24 (Before 2.90(AAHL.2)C0), GS1900-24E (Before 2.90(AAHK.2)C0), GS1900-24EP (Before 2.90(ABTO.2)C0), GS1900-24HPv2 (Before 2.90(ABTP.2)C0), GS1900-48 (Before 2.90(AAHN.2)C0), GS1900-48HPv2 (Before 2.90(ABTQ.2)C0)cpe:2.3:o:zyxel:gs1900-8_firmware:*:*:*:*:*:*:*:*cpe:2.3:o:zyxel:gs1900-8hp_firmware:*:*:*:*:*:*:*:*cpe:2.3:o:zyxel:gs1900-10hp_firmware:*:*:*:*:*:*:*:*cpe:2.3:o:zyxel:gs1900-16_firmware:*:*:*:*:*:*:*:*cpe:2.3:o:zyxel:gs1900-24_firmware:*:*:*:*:*:*:*:*cpe:2.3:o:zyxel:gs1900-24e_firmware:*:*:*:*:*:*:*:*cpe:2.3:o:zyxel:gs1900-24ep_firmware:*:*:*:*:*:*:*:*cpe:2.3:o:zyxel:gs1900-24hpv2_firmware:*:*:*:*:*:*:*:*cpe:2.3:o:zyxel:gs1900-48_firmware:*:*:*:*:*:*:*:*cpe:2.3:o:zyxel:gs1900-48hpv2_firmware:*:*:*:*:*:*:*:*CWE-121

03 / Action Plan

Recommendations

  1. 01
    Update the Firmware Now

    Install Zyxel's patched firmware for your GS1900 model without delay (for example, 2.90(AAHL.2)C0 for the GS1900-24). Patching is the direct fix for CVE-2026-7273, and every unpatched switch on your network remains open to unauthenticated command execution. If a patch is not available for a device, CISA advises discontinuing its use.

  2. 02
    Replace Default and Weak Credentials

    More than half of the compromised switches were still using factory-default logins. Change every default and reused password on your GS1900 devices to strong, unique credentials, and confirm no device is reachable with out-of-the-box settings.

  3. 03
    Restrict the Management Interface

    Limit access to the switch web/CGI management interface to a trusted administrative network or VLAN, and make sure these devices are not exposed to untrusted or internet-facing segments. This shrinks the pool of hosts that could send the malicious request.

  4. 04
    Watch for Attacker Behavior on the Switch

    Alert on and block unexpected outbound TFTP transfers from switch management interfaces to external hosts, and check devices for the collector script and its staged output file (/home/web/tmp/info.txt). Because GreyNoise withheld the exploitation IP address, these host- and network-level behaviors are the most reliable signals for this activity.

  5. 05
    Vulnerability Management

    Maintain an up-to-date inventory of network devices and their firmware versions so security updates can be applied quickly when vendors release them. Prioritize internet-adjacent and infrastructure devices such as switches, routers, and firewalls, which give attackers broad visibility and control once compromised.


04 / Adversary Behaviour

MITRE ATT&CK TTPs

T1587
Resource Development
Develop Capabilities
T1587.001
Resource Development
Develop Capabilities › Malware
T1608
Resource Development
Stage Capabilities
T1608.001
Resource Development
Stage Capabilities › Upload Malware
T1588
Resource Development
Obtain Capabilities
T1588.006
Resource Development
Obtain Capabilities › Vulnerabilities
T1190
Initial Access
Exploit Public-Facing Application
T1059
Execution
Command and Scripting Interpreter
T1059.006
Execution
Command and Scripting Interpreter › Python
T1027
Defense Evasion
Obfuscated Files or Information
T1027.002
Defense Evasion
Obfuscated Files or Information › Software Packing
T1105
Command and Control
Ingress Tool Transfer
T1119
Collection
Automated Collection
T1005
Collection
Data from Local System

05 / Sources

References & Patch Links

Patch Link
References

Reduce real exposure. Not just vulnerability volume.