DEV Community

StarkMan
StarkMan

Posted on

Why CISA gave agencies three days to patch CVE-2026-7273 in Zyxel GS1900 switches

Why CISA gave agencies three days to patch CVE-2026-7273 in Zyxel GS1900 switches

CISA added CVE-2026-7273 to the Known Exploited Vulnerabilities catalog on 21 September 2026 and set a remediation deadline of 24 September 2026. Three days is a short window even by KEV standards, and the reason is visible in the entry itself. The vulnerability is reachable without credentials from the local network, it leads to command execution on the device, and there is evidence that someone is already using it.

The vulnerability in one paragraph

CVE-2026-7273 is a stack-based buffer overflow in the CGI program of the Zyxel GS1900 series switch firmware. A crafted HTTP request overflows a stack buffer, and the overflow can be turned into OS command execution. Zyxel published the advisory on 16 June 2026 with a CVSS 3.1 base score of 8.8 and the vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The adjacent-network attack vector, no privileges required, and no user interaction explain why the flaw is treated as urgent despite needing local network access.

What the KEV entry adds

The KEV record requires forensic triage, which means agencies have to determine whether a compromise happened before the patch was applied, not simply install the update. Known ransomware campaign use is listed as unknown, so the catalog does not tie this flaw to a specific ransomware operation. The due date of 24 September 2026 applies to federal civilian executive branch agencies under Binding Operational Directive 26-04, which prioritizes remediation of vulnerabilities that grant total control of an asset after exploitation.

Who is actually exposed

The vulnerable interface is the switch's web management CGI. That changes the exposure picture compared with a remote internet-facing service. A GS1900 switch is typically reachable from the network segment it serves, so any host on that segment can attempt the request. Flat networks, guest VLANs that can route to management addresses, and switches with remote management enabled are the configurations where the adjacent-network requirement is easy to meet.
A ZoomEye search for Zyxel devices whose HTML title contains GS1900 returns 5,920 matching instances using the query app="Zyxel" && title="GS1900". The number counts fingerprint matches, not confirmed vulnerable firmware, and it does not tell you whether those devices are reachable from an untrusted segment. A CVE-scoped query, vul.cve="CVE-2026-7273", returned no indexed assets, so the product fingerprint is the only useful signal available right now.

Affected models and fixed firmware

Model Affected version Patch
GS1900-8 2.90(AAHH.1)C0 and earlier 2.90(AAHH.2)C0
GS1900-8HP 2.90(AAHI.1)C0 and earlier 2.90(AAHI.2)C0
GS1900-10HP 2.90(AAZI.1)C0 and earlier 2.90(AAZI.2)C0
GS1900-16 2.90(AAHJ.1)C0 and earlier 2.90(AAHJ.2)C0
GS1900-24 2.90(AAHL.1)C0 and earlier 2.90(AAHL.2)C0
GS1900-24E 2.90(AAHK.1)C0 and earlier 2.90(AAHK.2)C0
GS1900-24EP 2.90(ABTO.1)C0 and earlier 2.90(ABTO.2)C0
GS1900-24HPv2 2.90(ABTP.1)C0 and earlier 2.90(ABTP.2)C0
GS1900-48 2.90(AAHN.1)C0 and earlier 2.90(AAHN.2)C0
GS1900-48HPv2 2.90(ABTQ.1)C0 and earlier 2.90(ABTQ.2)C0

Zyxel states that on-market products outside this list are unaffected. The NVD record is marked Deferred, so the vendor table is the reference for version ranges.

What to do before the deadline

Patch the ten models listed above to the fixed firmware. Zyxel's advisory links the downloads.
If the update cannot be applied immediately, cut off the path to the CGI interface. Move management to a dedicated out-of-band network, disable remote management, and make sure client and guest segments cannot route to the switch's web interface. Those steps do not fix the overflow, but they remove the adjacent-network position the exploit needs.
Then do the triage step the KEV entry asks for. Check the switch configuration for unexpected accounts or changed settings, review logs for requests to the CGI endpoint, and treat a device that was reachable from an untrusted segment as a possible entry point rather than a device that merely needs an update.

References

Top comments (0)