Trending: On-device modelsSearch
iHeartGeek
iTECH

Zyxel's GS1900 switches join CISA's exploited list

CISA has added a command-execution flaw affecting ten Zyxel GS1900 switch models to the catalogue of vulnerabilities known to be exploited in the wild, with a federal remediation deadline of 24 September.

Two Zyxel GS1900 series rack switches photographed from the front on a white background, with callouts marking the 48-port model's 48 Gigabit Ethernet RJ-45 ports and two SFP ports and the 48HP model's 24 PoE ports, 24 further RJ-45 ports and two SFP ports.

CISA added a flaw in Zyxel's GS1900 series switches to the catalogue of vulnerabilities known to be exploited in the wild on 21 September, four months after the vendor shipped fixes for it. US federal civilian agencies have until 24 September to apply mitigations, and the listing also asks them to run forensic triage on any device that was exposed.

What the flaw does

CVE-2026-7273 is a stack-based buffer overflow in the CGI program of the switch firmware. Zyxel describes it as reachable from the local network by an unauthenticated attacker, who can send a crafted HTTP request to the switch's web interface and potentially run operating system commands. NVD scores it 8.8 out of 10 under CVSS 3.1, with the attack vector marked adjacent, no privileges required and no user interaction needed.

Which switches are affected

Ten models appear in the vendor advisory: the GS1900-8, GS1900-8HP, GS1900-10HP, GS1900-16, GS1900-24, GS1900-24E, GS1900-24EP, GS1900-24HPv2, GS1900-48 and GS1900-48HPv2. The fixes sit in the same 2.90 release train as the vulnerable builds, with the final digit of the firmware string bumped - on the GS1900-48HPv2, for instance, 2.90(ABTQ.1)C0 becomes 2.90(ABTQ.2)C0 - so a switch that reports a 2.90 build needs its exact revision checked rather than assumed. Zyxel says models outside the table are unaffected.

Why it is on the exploited list

The KEV catalogue is reserved for flaws with evidence of exploitation rather than theoretical risk, and each entry carries a deadline for federal agencies. CISA sets 24 September 2026 for this one, records that ransomware use is unknown and flags the flaw for forensic triage. Zyxel's own advisory is dated 16 June 2026 and credits Lei Gu, Jun Cao, Zhiqing Rui, Jingzheng Wu and Tianyue Luo of ISCAS with reporting the issue.

What to do about it

Administrators should move affected switches onto the patched firmware and treat the management interface as untrusted until they do. The flaw is only reachable from the adjacent network, so a switch whose web interface cannot be reached from user VLANs carries less immediate risk than one sitting on a flat network - but the remedy is the same firmware update either way.

Our opinion

The number that matters here is not the 8.8 but the four months. Zyxel fixed this in June and told its customers; CISA only added it to the exploited list in September, once someone had evidence that the bug was being used. Switches sit in the part of the estate that rarely gets rebooted, is seldom internet-facing and almost never wins a patching window, which is exactly the profile that lets a LAN-side bug stay useful for a season. An attacker who already has a foothold needs one unpatched access switch to widen it, and access switches are not usually the first thing anyone inventories. That is the case for treating the management plane of network gear as a security boundary in its own right, rather than as an internal detail behind the firewall. The three-day federal deadline does not force that discipline anywhere else, so for most networks the useful work this week is smaller and duller: find out which of the ten models are on the estate, and check each one's exact firmware revision instead of trusting the product name.