VYPR
High severity8.8NVD Advisory· Published Jun 16, 2026

CVE-2026-7273

CVE-2026-7273

Description

A stack-based buffer overflow in the CGI program of Zyxel GS1900 series switches allows LAN-based unauthenticated attackers to execute arbitrary OS commands.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A stack-based buffer overflow in the CGI program of Zyxel GS1900 series switches allows LAN-based unauthenticated attackers to execute arbitrary OS commands.

Vulnerability

A stack-based buffer overflow vulnerability exists in the CGI program of multiple Zyxel GS1900 series switch firmware versions. Affected models include GS1900-8 (up to 2.90(AAHH.1)C0), GS1900-8HP (up to 2.90(AAHI.1)C0), GS1900-10HP (up to 2.90(AAZI.1)C0), GS1900-16 (up to 2.90(AAHJ.1)C0), GS1900-24 (up to 2.90(AAHL.1)C0), GS1900-24E (up to 2.90(AAHK.1)C0), GS1900-24EP (up to 2.90(ABTO.1)C0), GS1900-24HPv2 (up to 2.90(ABTP.1)C0), GS1900-48 (up to 2.90(AAHN.1)C0), and GS1900-48HPv2 (up to 2.90(ABTQ.1)C0). The flaw is triggered via a crafted HTTP request sent to the device's CGI program. [1]

Exploitation

An attacker must be on the same LAN as the vulnerable switch and send a specially crafted HTTP request to the CGI program. No authentication is required to reach the vulnerable code path. The attacker sends an oversized input that overflows a fixed-size stack buffer, corrupting adjacent memory and allowing control of execution flow. [1]

Impact

Successful exploitation enables an unauthenticated, LAN-based attacker to execute arbitrary operating system commands on the switch. This can lead to full compromise of the device, including data exfiltration, network manipulation, and potential pivot attacks within the local network. The CIA impact is high, as the attacker gains command execution with the privileges of the CGI process. [1]

Mitigation

Zyxel has released patched firmware versions for all affected models: GS1900-8 (2.90(AAHH.2)C0), GS1900-8HP (2.90(AAHI.2)C0), GS1900-10HP (2.90(AAZI.2)C0), GS1900-16 (2.90(AAHJ.2)C0), GS1900-24 (2.90(AAHL.2)C0), GS1900-24E (2.90(AAHK.2)C0), GS1900-24EP (2.90(ABTO.2)C0), GS1900-24HPv2 (2.90(ABTP.2)C0), GS1900-48 (2.90(AAHN.2)C0), and GS1900-48HPv2 (2.90(ABTQ.2)C0). Users should upgrade to the latest available firmware for their model. No workarounds are provided in the advisory. [1]

AI Insight generated on Jun 16, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.