peter bassill · operator
$ cve CVE-2026-7273 JSON

CVE-2026-7273 KEV

8.8
HIGH · CVSS 3.1 · EPSS 2.5% (pctl 84)

Patch first

On CISA KEV — known exploited in the wild, due 2026-09-24.

Description

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS2.5% — more likely to be exploited than 84% of all CVEs
WeaknessCWE-121
On CISA KEVyes — remediate by 2026-09-24
Public exploitnone known
Published2026-06-16
Last modified2026-09-22

CISA KEV

NameZyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
Added2026-09-21
Due2026-09-24
Vendor / productZyxel / GS1900 Series Switches
Ransomware usenone reported

Affected (20)

VendorProduct
zyxelgs1900-10hp
zyxelgs1900-10hp firmware
zyxelgs1900-16
zyxelgs1900-16 firmware
zyxelgs1900-24
zyxelgs1900-24 firmware
zyxelgs1900-24e
zyxelgs1900-24e firmware
zyxelgs1900-24ep
zyxelgs1900-24ep firmware
zyxelgs1900-24hpv2
zyxelgs1900-24hpv2 firmware
zyxelgs1900-48
zyxelgs1900-48 firmware
zyxelgs1900-48hpv2
zyxelgs1900-48hpv2 firmware
zyxelgs1900-8
zyxelgs1900-8 firmware
zyxelgs1900-8hp
zyxelgs1900-8hp firmware

References

→ the Explorer  ·  watch your stack  ·  NVD