type: cve · created: 2026-09-22 · updated: 2026-09-22 · tags: [cve] · confidence: medium · severity: high · affected_sectors: [global] · au_impact: false
A stack-based buffer overflow in the CGI program of Zyxel GS1900 series switches (CWE-121) lets a LAN-based, unauthenticated attacker execute OS commands through a crafted HTTP request; NVD rates it 8.8 high (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and it affects GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0. CISA added CVE-2026-7273 to its Known Exploited Vulnerabilities (KEV) Catalog on 21 September on evidence of active exploitation, which is what raises it above a routine vendor advisory: NVD published the flaw in June 2026, so the exploitation CISA cites is of a patchable, three-month-old defect in edge hardware that commonly sits outside server and endpoint patching cycles.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-7273 |
| CVSS | 8.8 (High) — CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Vendor / product | Zyxel — GS1900 series switches (GS1900-48HPv2 firmware through 2.90(ABTQ.1)C0) |
| Reported | 2026-09-22 (NVD published 16 June 2026) |