Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4505 articles · 223849 vulns · 37/41 feeds (7d)
← Back to list
8.8
CVE-2026-7273KEVEXPLOITEDPATCHED
zyxel · gs1900-8_firmware

CVE-2026-7273: A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABT

Description

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

Affected Products

VendorProductVersions
zyxelgs1900-8_firmware<= 2.90(ABTQ.1)C0, <= 2.90(AAHH.1)C0, <= 2.90(AAHI.1)C0, <= 2.90(AAZI.1)C0, <= 2.90(AAHJ.1)C0, <= 2.90(AAHL.1)C0, <= 2.90(AAHK.1)C0, <= 2.90(ABTO.1)C0, <= 2.90(ABTP.1)C0, <= 2.90(AAHN.1)C0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
zyxelgs1900-24_firmwarecve_cpe95%
zyxelgs1900-10hpcve_cpe95%
zyxelgs1900-24e_firmwarecve_cpe95%
zyxelgs1900-16cve_cpe95%
zyxelgs1900-24ep_firmwarecve_cpe95%

References

  • https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026(vendor-advisory)

Related News (8 articles)

Tier D
Help Net Security20h ago
Week in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents
→ No new info (linked only)
Tier E
Reddit r/cybersecurity5d ago
CISA just added CVE-2026-7273 affecting Zyxel GS1900 switches to its KEV catalog.
→ No new info (linked only)
Tier D
SecurityWeek5d ago
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
→ No new info (linked only)
Tier D
Help Net Security5d ago
Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)
→ No new info (linked only)
Tier D
BleepingComputer5d ago
CISA orders feds to patch Zyxel flaw exploited for data theft
→ No new info (linked only)
Tier D
The Hacker News5d ago
Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
→ No new info (linked only)
Tier B
CCCS Canada103d ago
Zyxel security advisory (AV26-603)
→ No new info (linked only)
Tier C
VulDB104d ago
CVE-2026-7273 | Zyxel GS1900-48 up to 2.90(ABTQ.1)C0 HTTP stack-based overflow
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026
CWECWE-121
PublishedJun 16, 2026
Last enriched104d agov2
Trending Score131🔥
Source articles8
Independent7
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-8508
CVE-2026-8508: An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions throug
Trending: 2
HIGHCVE-2026-6837
CVE-2026-6837: A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions
Trending: 1
HIGHCVE-2026-14818
CVE-2026-14818: A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versi
CRITICALCVE-2026-13206
Multiple Vulnerabilities in Zyxel's WAH7601 - OS Command Injection
HIGHCVE-2026-6374
Hardcoded Credentials in Zyxel WAH7601 Router

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 16, 2026
Added to CISA KEV
Jun 16, 2026
Discovered by ZDM
Jun 16, 2026
Updated: severity, cvssEstimate
Jun 16, 2026
Actively Exploited
Sep 22, 2026
Patch Available
Sep 22, 2026

Version History

v2
Last enriched 104d ago
v2Tier C104d ago

Updated severity to CRITICAL, added new affected products, and corrected CVSS estimate to 9.0.

severitycvssEstimate
via VulDB
v1104d ago

Initial creation