Skip to content
Rush Commerce
Software & Dev4 min read

Zyxel GS1900 flaw: 996 switches robbed, fix shipped in June

CVE-2026-7273 let a LAN attacker run commands on Zyxel GS1900 switches. 996 were looted across 48 countries — three months after Zyxel published the firmware.

The cheap managed switch in your wiring closet is a Linux box with a web server on it, and somebody just proved it. CISA added CVE-2026-7273 in Zyxel GS1900 series switches to the Known Exploited Vulnerabilities catalog on September 21, after GreyNoise found a threat actor had pulled configuration data off 996 of them across 48 countries. Zyxel shipped the firmware fix on June 16, 2026. The attacks came in August. That gap is the entire story.

What actually happened

CVE-2026-7273 is a stack-based buffer overflow in the CGI program of the GS1900 web interface. An attacker with LAN access and no credentials sends a crafted HTTP request and executes OS commands on the switch. CVSS 8.8. No login, no phishing step, no user interaction.

Zyxel's advisory covers ten models: GS1900-8, -8HP, -10HP, -16, -24, -24E, -24EP, -24HPv2, -48 and -48HPv2. The fix is the .2)C0 firmware build for your specific model — the string differs per SKU, so read the table rather than guessing.

GreyNoise reported the exploitation happened on or about August 17, roughly two months after the patch, and was first publicly documented in September. The actor — described as Chinese-speaking, and linked to earlier WordPress and Gitea campaigns — delivered the exploit in a Python script obfuscated with the commercial tool PyArmor. What came back out: device configuration, networking information, and hashed root-level credentials. Affected devices cluster in Italy, the US, Taiwan, South Korea and the EU.

Then the part that should sting. 564 of the 996 compromised switches were still on factory default credentials. For those, the buffer overflow was optional. Somebody could have simply logged in.

Why your network closet matters for your business

Switches are not in anybody's patch cycle. You patch laptops because an agent nags you. Nothing nags you about a $200 switch. It has no agent, no dashboard tile, and no owner — it was installed by whoever ran the cable, and it has been forwarding frames ever since. That is why a June patch was still unapplied in August.

"LAN access required" is not a mitigation. It is a description of where the attacker already is. Any compromised laptop, guest-Wi-Fi device, IP camera or contractor VPN session is on the LAN. Treating internal-only bugs as low priority is how you end up with stolen switch configs and hashed root hashes in somebody else's hands.

Default credentials are the actual finding. More than half the victims never changed them. If you do nothing else after reading this, log into every managed switch, AP, NAS, camera NVR and printer you own and change the admin password. That is an afternoon, not a project.

Stolen config equals a network map. VLAN layout, management IPs, uplink topology, SNMP strings. That is reconnaissance for whatever comes next, and it was taken quietly — a looted switch does not misbehave in any way a user would report.

Practical sequence: inventory the model and firmware string on every GS1900 you have, apply the .2)C0 build, rotate admin credentials and SNMP community strings, put switch management on a VLAN that only your admin workstations can reach, and check the config for changes you cannot account for. A patch closes the door; it tells you nothing about August.

Key takeaways

  • CVE-2026-7273 is a CVSS 8.8 unauthenticated stack-based buffer overflow in the Zyxel GS1900 web CGI, exploitable from the LAN
  • Zyxel published fixed firmware June 16, 2026; GreyNoise dates the attacks to on or about August 17
  • 996 switches across 48 countries had configs, networking data and hashed root credentials exfiltrated
  • 564 of those victims were still running factory default credentials — the exploit was not even necessary
  • Ten models affected, from GS1900-8 to GS1900-48HPv2; the fixed build string differs per model
  • CISA added it to KEV on September 21 with a federal remediation deadline this week under BOD 26-04
  • Rotate credentials, apply firmware, and segment switch management away from general user traffic

Nobody owns the switch. That is the real vulnerability, and it is fixable in a week. We inventory every managed device on your network — firmware string, credentials, who can reach its admin page — then hand you a cadence that survives us leaving. Ask for a network device audit, or see how we handle infrastructure we did not build.

Sources: Zyxel, CISA, Help Net Security.

  • #zyxel-gs1900
  • #cve-2026-7273
  • #cisa-kev
  • #network-security
  • #small-business-it
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.