CVE-2026-7273 in Zyxel GS1900 switches allows unauthenticated OS command execution
A stack-based buffer overflow in the CGI program of Zyxel GS1900 switch firmware (CVE-2026-7273, CVSS 8.8) allows OS command execution from an adjacent network with no credentials. CISA added it to the Known Exploited Vulnerabilities catalog on 21 September 2026, with patches released for 10 models.
- CVSS 3.1 score 8.8, vector AV:A/AC:L/PR:N/UI:N — adjacent network access, no credentials
- CISA added CVE-2026-7273 to its KEV catalog on 21 September 2026, deadline 24 September
- 10 GS1900 models affected, including GS1900-8, -24 and -48, firmware 2.90 and earlier
- ZoomEye returns 5,920 matches for Zyxel GS1900, an inventory signal, not reachability
Read next
Security