Back to Articles
high

HIGH: Zyxel GS1900 Switch Flaw CVE-2026-7273 Exploited on 996 Devices

A suspected Chinese-speaking threat actor exploited CVE-2026-7273, a CVSS 8.8 unauthenticated buffer overflow in Zyxel GS1900 switches, to steal configurations and hashed root credentials from 996 devices in 48 countries. CISA added it to KEV with a September 24 deadline, and fixed firmware has been available since June.

By Danny Mercer, CISSP — Lead Security Analyst Sep 22, 2026
Is your business exposed? Our McKinney-based security team can assess your risk for free.
Share:

There is a special category of network gear that everybody owns and nobody thinks about. It sits in a closet, it blinks, it was configured once by someone who no longer works there, and it has been quietly forwarding packets since the Obama administration. The Zyxel GS1900 smart managed switch lives in that category for a lot of small offices, and this week it became the center of an active exploitation campaign that has already swept up nearly a thousand devices around the world.

On September 21, 2026, CISA added CVE-2026-7273 to its Known Exploited Vulnerabilities catalog and gave federal civilian agencies until Thursday, September 24, to patch or pull the affected hardware under Binding Operational Directive 26-04. Three days is not a lot of runway, and the reason for the rush is that GreyNoise has documented a suspected Chinese-speaking threat actor using the flaw to break into unpatched GS1900 switches and walk off with their configurations, network details and hashed root credentials. By GreyNoise's count, 996 switches across 48 countries have been compromised so far.

The frustrating part is that this is not a zero-day. Zyxel shipped the fix back on June 16, 2026. That leaves roughly three months of patch window that a lot of organizations simply did not use, which is about as predictable as it is painful.

The Technical Details

CVE-2026-7273 is a stack-based buffer overflow in the CGI program that powers the GS1900 web management interface. Zyxel's advisory describes it plainly, saying the bug "could allow a LAN-based, unauthenticated attacker to execute OS commands on the device via a specially crafted HTTP request." The CVSS score is 8.8, which lands it in High territory rather than Critical, and the main thing holding it back from a higher number is the adjacent network requirement. The attacker needs to reach the management interface, and in a sane world that interface is not sitting on the open internet.

We do not live in a sane world. Plenty of these switches have their web interface reachable from networks that should never touch it, whether that means a flat office LAN shared with guest Wi-Fi, a management VLAN that was never actually isolated, or a port forward someone set up years ago to make remote troubleshooting easier. Once an attacker has any foothold on that segment, or the interface is exposed outright, the lack of authentication means there is nothing standing between a crafted request and code execution on the switch.

The affected hardware spans ten models. The GS1900-8 is vulnerable on 2.90(AAHH.1)C0 and earlier and is fixed in 2.90(AAHH.2)C0. The GS1900-8HP needs 2.90(AAHI.2)C0, the GS1900-10HP needs 2.90(AAZI.2)C0, and the GS1900-16 needs 2.90(AAHJ.2)C0. On the 24 port side, the GS1900-24 is fixed in 2.90(AAHL.2)C0, the GS1900-24E in 2.90(AAHK.2)C0, the GS1900-24EP in 2.90(ABTO.2)C0 and the GS1900-24HPv2 in 2.90(ABTP.2)C0. The 48 port GS1900-48 and GS1900-48HPv2 are fixed in 2.90(AAHN.2)C0 and 2.90(ABTQ.2)C0 respectively. The pattern is easy to remember. If your build string ends in ".1)C0" or anything older, you are vulnerable, and ".2)C0" is where you want to be.

Credit for the original discovery goes to Lei Gu, Jun Cao, Zhiqing Rui, Jingzheng Wu and Tianyue Luo of the Institute of Software, Chinese Academy of Sciences (ISCAS), who reported the bug to Zyxel ahead of the June advisory.

How Exploitation Looks in the Wild

GreyNoise's reporting puts the first publicly documented exploitation at September 17, while coverage from Help Net Security traces the compromises back to roughly mid August. Either way, the attacker has had weeks of quiet access on some of these devices before anyone started talking about it publicly.

The tooling is more polished than your average botnet spray. The operator used a Python exploit script obfuscated with PyArmor, a commercial protection tool, which tells you someone cared enough to make analysis annoying. Once the overflow landed, the payload used TFTP to pull down and run a custom collector script whose job was to harvest the switch configuration, networking information and hashed root level credentials. The script is built around the GS1900-24 running firmware 2.10 through 2.90, with command line options to adapt it to other firmware variants.

One detail from the reporting should make every MSP wince. Of the 996 compromised switches, 564 were still running factory default credentials. That means more than half the victims would have been in trouble even without a memory corruption bug, and the exploit was just the more elegant way in. Default passwords on network infrastructure in 2026 remain the gift that keeps on giving, and attackers keep cashing it in.

Victims are concentrated in Italy, the United States, Taiwan, South Korea and France, with the rest spread across other EU nations and beyond. Nothing about the target list suggests a narrowly focused espionage operation. This looks like opportunistic collection at scale, where the switches are useful as reconnaissance sources, credential banks and potential pivot points into whatever network sits behind them.

The same actor is not a one-trick operator either. GreyNoise and other researchers tie this activity to a broader campaign that has exploited more than a dozen other vulnerabilities, including flaws in WordPress, Gitea, UniFi OS, Flowise, Proxmox VE, Nuclio, SENAITE LIMS, the Linux kernel and Palo Alto Networks GlobalProtect. Acronis tracks a cluster it calls Red Heron that may overlap. When someone is working through a list that long, your unpatched switch is not special. It is just next.

It is also worth remembering the broader Zyxel context. CISA now tracks 13 exploited Zyxel vulnerabilities across routers, switches, firewalls and NAS devices. Zyxel gear is everywhere in the SMB market and frequently ships as default ISP equipment, which makes it an attractive target for anyone who wants volume.

What To Do Right Now

The first job is inventory, and I say that knowing how many people just groaned. You cannot patch a switch you forgot you owned. Pull the list of every GS1900 in your environment or in each client environment, note the exact model and firmware string, and compare it against the fixed versions above. If you manage a lot of sites, a quick scan for the GS1900 web interface banner on internal ranges will surface the stragglers that never made it into the asset register.

Next, update the firmware. Zyxel's fixed builds have been available since June, so there is no waiting on the vendor here. Download from Zyxel's official support portal, apply during a maintenance window, and verify the new build string afterward. A switch reboot will blip whatever is plugged into it, so plan accordingly for anything that powers phones or cameras over PoE.

Patching alone is not enough if the device was already compromised, and given the timeline, some were. Because the collector script grabbed hashed root credentials and full configurations, you should treat any switch that was running vulnerable firmware with an exposed management interface as potentially burned. Change the admin password on every GS1900 regardless of whether you see evidence of compromise, and make it unique per device. If the switch configuration contained SNMP community strings, RADIUS shared secrets or any other credentials, rotate those too, because the attacker may have them now. Kill any factory default logins on the spot.

Then lock down the management plane, which is the fix that actually outlives this particular CVE. The web interface should only be reachable from a dedicated management VLAN or a jump host, never from user networks, guest networks or the internet. Use access control lists on the switch to restrict which source addresses can talk to its HTTP and HTTPS services. If remote management is genuinely required, put it behind a VPN rather than a port forward.

For detection, look at firewall and flow logs for unexpected TFTP traffic originating from switch management addresses, since that is how the collector script was fetched. Switches do not usually initiate outbound TFTP sessions on their own, so any hit there deserves a closer look. Review HTTP requests to switch management interfaces from hosts that have no business administering network gear, and check configuration change logs for anything that happened between mid August and your patch date. GreyNoise has published indicators of compromise, and it is worth pulling those into your SIEM or firewall blocklists today.

If a switch shows signs of tampering and you have the option, a factory reset followed by a clean firmware install and a rebuilt configuration is the safest path. Restoring a backup taken after the compromise just hands the attacker's changes right back.

The Bigger Picture

Switches have a way of disappearing from security conversations because they are not endpoints and they are not firewalls. They do not run EDR, they rarely feed logs to anyone, and they are almost never part of a monthly patch cycle. That is exactly why they make such good targets. An attacker who owns a switch can map the network, harvest credentials and quietly sit in a place most defenders never check. This campaign is a reminder that "boring" infrastructure deserves the same patch discipline as everything else, especially when the vendor had a fix on the shelf for three months.

MSP Angle

Clients with GS1900 switches in the closet are exactly the kind who assume networking equipment runs itself, so this is a strong opener for a network infrastructure assessment that covers firmware levels, default credentials and management plane exposure across every site. Package the findings into a recurring network device patching and configuration monitoring service, and you turn a one-time scare into monthly revenue that covers the gear nobody else is watching.

References

Concerned about this threat?

Our security team can assess your exposure and recommend immediate actions.

Get a Free Assessment →