HIGHVulnerability

CVE-2026-7273

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

Properties

severity
HIGH
product
GS1900 Series Switches
vulnerabilityName
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
dueDate
2026-09-24
requiredAction
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discon
dateAdded
2026-09-21
score
8.8
cve_id
CVE-2026-7273
signal_observed_at
2026-09-21T23:06:15+00:00
vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendorProject
Zyxel
published_at
2026-06-16T03:16:13.557
last_modified
2026-09-21T20:17:32.970

Related Entities (4)

DESCRIBES (1)

[KEVEntry]Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Stack-based Buffer Overflow

KNOWN_EXPLOITED (1)

[Source]CISA KEV

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-7273 — Ninja Signal Threat Intelligence | Ninja Signal