CVE-2026-7273High· 8.8▾ Abyssal⚠ Exploited in the wildPoC availableA stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via …
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 48.4 · likelihood 0.1 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 21.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Sep 24, 2026
0.3%
Last analysed / modified upstream
Added to the CISA catalog on Sep 21, 2026. Federal remediation due Sep 24, 2026. View catalog ↗
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
gs1900-8_firmware < 2.90\(aahh.2\)c0gs1900-8hp_firmware < 2.90\(aahi.2\)c0gs1900-10hp_firmware < 2.90\(aazi.2\)c0gs1900-16_firmware < 2.90\(aahj.2\)c0gs1900-24_firmware < 2.90\(aahl.2\)c0gs1900-24e_firmware < 2.90\(aahk.2\)c0gs1900-24ep_firmware < 2.90\(abto.2\)c0gs1900-24hpv2_firmware < 2.90\(abtp.2\)c0gs1900-48_firmware < 2.90\(aahn.2\)c0gs1900-48hpv2_firmware < 2.90\(abtq.2\)c0Upgrade past the affected range:
gs1900-8_firmware 2.90\(aahh.2\)c0gs1900-8hp_firmware 2.90\(aahi.2\)c0gs1900-10hp_firmware 2.90\(aazi.2\)c0gs1900-16_firmware 2.90\(aahj.2\)c0gs1900-24_firmware 2.90\(aahl.2\)c0gs1900-24e_firmware 2.90\(aahk.2\)c0gs1900-24ep_firmware 2.90\(abto.2\)c0gs1900-24hpv2_firmware 2.90\(abtp.2\)c0gs1900-48_firmware 2.90\(aahn.2\)c0gs1900-48hpv2_firmware 2.90\(abtq.2\)c0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2017-6884High· 8.8A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8
CVE-2024-11667High· 7.5A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V…
CVE-2025-22457Critical· 9.0A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code…
CVE-2025-0282Critical· 9.0A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve…
CVE-2026-26731High· 8.8TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 function.
CVE-2026-61674Critical· 9.2Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows