chiprook
← Security
SecuritySeptember 29, 2026, 20:21

CVE-2026-7273 in Zyxel GS1900 switches allows unauthenticated OS command execution

A stack-based buffer overflow in the CGI program of Zyxel GS1900 switch firmware (CVE-2026-7273, CVSS 8.8) allows OS command execution from an adjacent network with no credentials. CISA added it to the Known Exploited Vulnerabilities catalog on 21 September 2026, with patches released for 10 models.

CVE-2026-7273 in Zyxel GS1900 switches allows unauthenticated OS command execution
#Zyxel#CISA
Read next
Security

Critical Bifrost AI Gateway Flaw Allows Unauthenticated Command Execution

Security

Attackers exploit Issabel Framework flaw enabling unauthenticated OS command execution

Security

Attacker compromised nearly 1,000 Zyxel switches via CVE-2026-7273

Security

Critical Next.js ImageResponse flaw allows server code execution