{"id":"CVE-2026-7273","title":"A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via …","summary":"A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via …","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-121"],"vendor":"zyxel","product":"gs1900-8_firmware","affected":["gs1900-8_firmware < 2.90\\(aahh.2\\)c0","gs1900-8hp_firmware < 2.90\\(aahi.2\\)c0","gs1900-10hp_firmware < 2.90\\(aazi.2\\)c0","gs1900-16_firmware < 2.90\\(aahj.2\\)c0","gs1900-24_firmware < 2.90\\(aahl.2\\)c0","gs1900-24e_firmware < 2.90\\(aahk.2\\)c0","gs1900-24ep_firmware < 2.90\\(abto.2\\)c0","gs1900-24hpv2_firmware < 2.90\\(abtp.2\\)c0","gs1900-48_firmware < 2.90\\(aahn.2\\)c0","gs1900-48hpv2_firmware < 2.90\\(abtq.2\\)c0"],"patched":["gs1900-8_firmware 2.90\\(aahh.2\\)c0","gs1900-8hp_firmware 2.90\\(aahi.2\\)c0","gs1900-10hp_firmware 2.90\\(aazi.2\\)c0","gs1900-16_firmware 2.90\\(aahj.2\\)c0","gs1900-24_firmware 2.90\\(aahl.2\\)c0","gs1900-24e_firmware 2.90\\(aahk.2\\)c0","gs1900-24ep_firmware 2.90\\(abto.2\\)c0","gs1900-24hpv2_firmware 2.90\\(abtp.2\\)c0","gs1900-48_firmware 2.90\\(aahn.2\\)c0","gs1900-48hpv2_firmware 2.90\\(abtq.2\\)c0"],"published":"2026-06-16","updated":"2026-09-22","sourceUpdated":"2026-09-22T12:10:51.067","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-7273","references":[{"url":"https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026","label":"security@zyxel.com.tw"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-7273","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitation","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","cve.org","exploit-available"],"epss":0.01987,"epssPercentile":0.7972,"kev":true,"kevDateAdded":"2026-09-21","kevDueDate":"2026-09-24","kevRansomware":false,"exploited":true,"exploitAvailable":true,"ssvc":{"exploitation":"active","automatable":"no","technicalImpact":"total","timestamp":"2026-09-21T19:40:05.862596Z"},"ingestedAt":"2026-09-21T19:51:58.870Z","slug":"CVE-2026-7273","body":"## Overview\n\nA stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.\n\n## Affected\n\n- `gs1900-8_firmware < 2.90\\(aahh.2\\)c0`\n- `gs1900-8hp_firmware < 2.90\\(aahi.2\\)c0`\n- `gs1900-10hp_firmware < 2.90\\(aazi.2\\)c0`\n- `gs1900-16_firmware < 2.90\\(aahj.2\\)c0`\n- `gs1900-24_firmware < 2.90\\(aahl.2\\)c0`\n- `gs1900-24e_firmware < 2.90\\(aahk.2\\)c0`\n- `gs1900-24ep_firmware < 2.90\\(abto.2\\)c0`\n- `gs1900-24hpv2_firmware < 2.90\\(abtp.2\\)c0`\n- `gs1900-48_firmware < 2.90\\(aahn.2\\)c0`\n- `gs1900-48hpv2_firmware < 2.90\\(abtq.2\\)c0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `gs1900-8_firmware 2.90\\(aahh.2\\)c0`\n- `gs1900-8hp_firmware 2.90\\(aahi.2\\)c0`\n- `gs1900-10hp_firmware 2.90\\(aazi.2\\)c0`\n- `gs1900-16_firmware 2.90\\(aahj.2\\)c0`\n- `gs1900-24_firmware 2.90\\(aahl.2\\)c0`\n- `gs1900-24e_firmware 2.90\\(aahk.2\\)c0`\n- `gs1900-24ep_firmware 2.90\\(abto.2\\)c0`\n- `gs1900-24hpv2_firmware 2.90\\(abtp.2\\)c0`\n- `gs1900-48_firmware 2.90\\(aahn.2\\)c0`\n- `gs1900-48hpv2_firmware 2.90\\(abtq.2\\)c0`","depth":"abyssal","depthScore":74,"depthScoreParts":{"impact":48.4,"likelihood":0.4,"exploitation":25,"ransomware":0},"changes":[{"seq":208876,"id":"CVE-2026-7273","ts":1790053140459,"field":"kev","old":"false","new":"true"}]}