Zyxel GS1900-48HPv2 LAN RCE exploited in wild (CVE-2026-7273)
CVE-2026-7273
CVE-2026-7273: Zyxel GS1900-48HPv2 firmware through 2.90(ABTQ.1)C0 allows LAN-based unauthenticated OS command execution (CVSS 8.8). Update firmware now.
Actively exploited in the wild - CVE-2026-7273 is a high-severity stack-based buffer overflow in the Zyxel GS1900-48HPv2 switch firmware (through 2.90(ABTQ.1)C0) that grants a LAN-based, unauthenticated attacker OS command execution via a crafted HTTP request. No user interaction or credentials are required - isolate affected switches until patched.
Overview
The Zyxel GS1900-48HPv2 is a 48-port managed gigabit switch with PoE, commonly deployed in small and mid-sized business access layers. Its CGI program, the web-facing component that handles administrative HTTP requests, fails to validate the length of input before copying it to a fixed-size stack buffer. A crafted HTTP request overflows that buffer and can redirect execution flow, letting an attacker run operating system commands with the privileges of the web service.
The CVSS score of 8.8 reflects the combination of low attack complexity, no privileges required, and no user interaction. The one mitigating factor is the attack vector: ADJACENT_NETWORK. The attacker must already be on the same Layer 2 or Layer 3 segment as the switch, or reach its management interface. That typically means an insider, a compromised device on the LAN, or an attacker who has already established a foothold on the internal network.
Impact
Successful exploitation gives the attacker command execution on the device itself. From there, the practical consequences are:
- Full control of switch configuration, including VLANs, port mirroring, and ACLs
- Traffic interception or redirection via span ports and routing changes
- Use of the switch as a pivot point into segmented internal networks
- Persistence through modified startup configuration
Because the flaw is in the web management CGI, any switch with the HTTP/HTTPS interface reachable from an untrusted segment is exposed.
Remediation and Mitigation
Zyxel has published firmware addressing CVE-2026-7273. Administrators running GS1900-48HPv2 units on 2.90(ABTQ.1)C0 or earlier should upgrade to the latest available firmware from the Zyxel support portal.
If immediate upgrade is not possible:
- Restrict management interface access to a dedicated, tightly controlled management VLAN.
- Disable HTTP and HTTPS management on any interface reachable from user or guest segments.
- Apply ACLs on upstream switches to block access to the GS1900 management ports from untrusted subnets.
- Monitor switch logs and upstream firewall logs for malformed HTTP requests targeting the device.
Given confirmed in-the-wild exploitation, patching should be treated as time-sensitive rather than routine. Data breach reports are available at breach reports and cybersecurity news at security news.
Security Insight
The exploit mechanics here - a length-unchecked copy in a CGI handler - are among the oldest classes of memory-safety bugs still shipping in embedded network gear. What stands out is the exploitation-in-the-wild confirmation: attackers are actively targeting SMB-class switches, not just edge firewalls and VPN concentrators. That suggests an operational shift toward the unglamorous, under-monitored middle of the network, where firmware lags for years and management interfaces often sit on flat internal VLANs with no segmentation. Vendors that keep CGI-based management planes in production hardware are effectively shipping a known-bad design pattern; buyers should treat memory-safe management architecture as a procurement criterion, not an afterthought.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
An issue was discovered in SMS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, Mod...
HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have a stack buffer overflow that leads to a Denial of Service...
Aida64 Engineer 6.10.5200 contains a buffer overflow vulnerability in the CSV logging configuration that allows attackers to execute malicious code by crafting a specially designed payload. Attackers ...
Ayukov NFTP client 1.71 contains a buffer overflow vulnerability in the SYST command handling that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted SYST comman...