CVE-2026-7273: Zyxel GS1900-48HPv2 Stack Buffer Overflow RCE Vulnerability
A stack-based buffer overflow flaw exists in the web interface of Zyxel GS1900-48HPv2network switches. An attacker on the same local network can send a specially crafted HTTP request to the affected switch and execute arbitrary commands without needing credentials. This is a serious vulnerability because the attacker requires no authentication and the attack works reliably across local network segments.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.8 HIGH · CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-121
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-16 / 2026-06-18
NVD description (verbatim)
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-7273 is a stack-based buffer overflow (CWE-121) in the CGI application layer of the Zyxel GS1900-48HPv2 managed switch. The vulnerability exists in firmware versions through 2.90(ABTQ.1)C0 and allows stack memory corruption via a malformed HTTP request. Successful exploitation leads to arbitrary OS command execution in the context of the web server process, typically with elevated privileges on the switch. The attack vector is adjacent network (AV:A), requires no user interaction, and bypasses all authentication controls.
Business impact
Compromise of a Zyxel GS1900-48HPv2 switch in your network infrastructure could lead to unauthorized access to all traffic passing through the device, modification of network configurations, deployment of persistent backdoors, and potential lateral movement into connected systems. In environments where these switches manage critical network segments—such as data center core switches or distribution layer switches—the business impact extends to confidentiality breaches, operational downtime, and regulatory exposure if sensitive data transits the compromised device.
Affected systems
Zyxel GS1900-48HPv2 managed switches running firmware versions through 2.90(ABTQ.1)C0 are affected. Only units accessible from the local network are at direct risk; however, if the switch is reachable from a compromised host on that network segment, remote exploitation becomes possible. Organizations should inventory all GS1900-48HPv2 units and verify their current firmware version immediately.
Exploitability
This vulnerability is readily exploitable by attackers with network adjacency—no authentication is required and no user interaction is necessary. The attack is deterministic and likely requires minimal resources to craft. While currently not listed in CISA's Known Exploited Vulnerabilities catalog, the straightforward nature of HTTP-based buffer overflow attacks and the lack of authentication requirements suggest active exploitation risk is high if the vulnerability becomes publicly weaponized.
Remediation
Vendors should release and apply a firmware patch that addresses the stack buffer overflow in the CGI module. Users must upgrade affected switches to a patched firmware version when available from Zyxel. Until patching is possible, implement strong network segmentation to restrict which systems can reach the management interface of these switches, and monitor for anomalous HTTP requests directed at the CGI application. Disable remote management access if not required.
Patch guidance
Verify the current firmware version of each Zyxel GS1900-48HPv2 unit via the administrative web interface (System > Software) and compare against the affected version range (through 2.90(ABTQ.1)C0). Monitor Zyxel's security advisory and product support pages for release of a patched firmware version. Once a patch is available, test it in a non-production environment, then schedule controlled firmware updates during a maintenance window. Ensure automatic factory configuration restore is disabled during the update to preserve existing settings.
Detection guidance
Monitor HTTP access logs on the switch management interface for unusual request patterns, particularly long or malformed HTTP headers and payloads targeting the CGI application. Network-based detection can identify suspicious HTTP requests with abnormal sizes or character sequences directed at the switch's web interface. Endpoint detection on systems with access to the switch can flag unexpected process creation or OS command execution originating from the switch IP. Baseline normal management traffic and alert on deviations.
Why prioritize this
This vulnerability scores 8.8 (HIGH severity) due to the combination of unauthenticated local network access, direct OS command execution capability, and impact on all three security properties (confidentiality, integrity, availability). While KEV listing is not yet confirmed, the lack of authentication barriers and the criticality of network infrastructure make this a top-tier patching priority. Organizations operating these switches in production environments should treat this as urgent.
Risk score, explained
The CVSS 3.1 score of 8.8 reflects Attack Vector: Adjacent (network-local access required), Attack Complexity: Low (straightforward exploitation), Privileges Required: None (unauthenticated), User Interaction: None (automatic). The impact metrics are all set to High, indicating complete compromise of confidentiality, integrity, and availability. The score is elevated by the practical ease of exploitation, absence of authentication, and the trusted role network switches play in infrastructure.
Frequently asked questions
Can this vulnerability be exploited from the internet?
No. The attack vector is 'Adjacent Network' (AV:A), meaning the attacker must be on the same local network segment as the switch. However, if an attacker first compromises any device on that network segment, they can then exploit this switch. Proper network segmentation limits exposure.
Do I need to upgrade immediately if I'm not using Zyxel GS1900-48HPv2 switches?
No, this vulnerability is specific to the GS1900-48HPv2 model. However, check your inventory to confirm you do not have this model. Other Zyxel switch models may have separate vulnerabilities; perform a comprehensive device audit regardless.
What if a firmware patch is not available yet?
Apply compensating controls: restrict network access to the switch management interface using ACLs, disable remote management if not needed, place the switch on an isolated management VLAN, and enable logging and alerting on HTTP requests to the device. Monitor Zyxel advisories weekly for patch availability.
Can the vulnerable CGI application be disabled?
Consult Zyxel documentation for your firmware version to determine if the web management interface can be disabled in favor of SSH or SNMP-only management. Disabling the web interface would eliminate the attack surface for this specific flaw, but verify that all necessary management functions remain available through alternate means.
This analysis is based on the published CVE record as of 2026-06-18. Vendor advisories and patch availability may change. Always verify patching instructions and version numbers directly from Zyxel's official security advisories before deploying updates. This document does not constitute a substitute for professional security consultation. Organizations should conduct their own risk assessments based on their network topology and exposure. Source: NVD (public-domain), retrieved 2026-07-24. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2018-25383HIGHFree MP3 CD Ripper 2.8 Stack Overflow – ROP and DEP Bypass Risk
- CVE-2025-52292HIGHGPAC MP4Box Stack Buffer Overflow Denial of Service
- CVE-2025-66280HIGHQNAP Integer Overflow Vulnerability: Patch & Risk Assessment
- CVE-2026-10062HIGHTRENDnet TEW-432BRP Stack Overflow – EOL Hardware Risk
- CVE-2026-10063HIGHTRENDnet TEW-432BRP Stack Overflow – End-of-Life Router Vulnerability
- CVE-2026-10065HIGHShibby Tomato 1.28 Stack Buffer Overflow in tomatodata.cgi
- CVE-2026-10066HIGHShibby Tomato Stack Buffer Overflow in UPS Service (RCE)
- CVE-2026-10067HIGHShibby Tomato 1.28 Stack Buffer Overflow in multimon.cgi