← Back to CVE List
Vulnerability Intelligence Report
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

CVE-2026-7273

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:0.32%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-121 ↗CWE-121 Stack-based buffer overflow

Affected Products & Versions

Vendor Product Affected Versions
Zyxel GS1900-48HPv2 firmware <= 2.90(ABTQ.1)C0 (affected)
Zyxel GS1900-8 firmware <= 2.90(AAHH.1)C0 (affected)
Zyxel GS1900-8HP firmware <= 2.90(AAHI.1)C0 (affected)
Zyxel GS1900-10HP firmware <= 2.90(AAZI.1)C0 (affected)
Zyxel GS1900-16 firmware <= 2.90(AAHJ.1)C0 (affected)
Zyxel GS1900-24 firmware <= 2.90(AAHL.1)C0 (affected)
Zyxel GS1900-24E firmware <= 2.90(AAHK.1)C0 (affected)
Zyxel GS1900-24EP firmware <= 2.90(ABTO.1)C0 (affected)
Zyxel GS1900-24HPv2 firmware <= 2.90(ABTP.1)C0 (affected)
Zyxel GS1900-48 firmware <= 2.90(AAHN.1)C0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
0.315%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityZyxel Corporation · Vendor · Taiwan
Reserved2026-04-28T06:21:36
Published2026-06-16T02:20:29
Last Updated2026-09-21T19:58:23

LINK COPIED TO CLIPBOARD