← back
CVE-2026-7273highunder attackCWE-121

CVE-2026-7273

51Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA.

ssvc Actcvss 8.8epss 1.3%
from disclosure to weapon
Published on NVDJun 16
CISA KEV+97d
exploitation probability
1.3%top 31% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2026-09-24

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

In short

A stack-based buffer overflow in the Zyxel GS1900-48HPv2 switch allows an attacker on the local network to send a specially crafted HTTP request that overflows memory and executes unauthorized commands on the device.

Technical detail

Stack-based buffer overflow in the CGI program of Zyxel GS1900-48HPv2 (firmware ≤2.90(ABTQ.1)C0) exploitable by unauthenticated LAN-based attackers via crafted HTTP requests, enabling arbitrary OS command execution with high impact on device integrity and confidentiality.

Summary generated and translated by AI from the official description.
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H