DEV Community

yutianle
yutianle

Posted on

Network segmentation decides whether CVE-2026-7273 in Zyxel GS1900 switches is reachable

Network segmentation decides whether CVE-2026-7273 in Zyxel GS1900 switches is reachable

CVE-2026-7273 is a stack-based buffer overflow in the CGI program of the Zyxel GS1900 switch firmware that can lead to OS command execution, and it needs only adjacent network access with no credentials. CISA added it to the Known Exploited Vulnerabilities catalog on 21 September 2026 with a deadline of 24 September 2026. The adjacent-network requirement is the detail that determines whether a given switch is exposed, and it is also the detail that network design can control.

What adjacent network access means here

The CVSS 3.1 vector is CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, with a base score of 8.8. The AV:A value means the attacker must be on the same or an adjacent network, not on the public internet. The PR:N value means no credentials are needed, and UI:N means nothing has to be clicked. Zyxel classifies the weakness as CWE-121.
The vulnerable component is the CGI program behind the switch's web management interface. A crafted HTTP request overflows a stack buffer, and the overwrite can be used to run OS commands on the device.

Where the exposure actually comes from

A GS1900 switch serves a network segment, so hosts on that segment can usually reach its management interface unless something prevents it. The exposure therefore comes from network design decisions rather than from internet-facing services:

  • A flat network where user devices and the switch's management address share a broadcast domain.
  • A guest or IoT VLAN that can route to management addresses.
  • Remote management left enabled on an interface reachable from client segments.
  • Management interfaces on the same VLAN as access ports, with no ACL between them. Each of these gives an attacker who is already on the network, or who has compromised a single endpoint, the position the exploit requires.

Which models are affected

Model Affected version Patch
GS1900-8 2.90(AAHH.1)C0 and earlier 2.90(AAHH.2)C0
GS1900-8HP 2.90(AAHI.1)C0 and earlier 2.90(AAHI.2)C0
GS1900-10HP 2.90(AAZI.1)C0 and earlier 2.90(AAZI.2)C0
GS1900-16 2.90(AAHJ.1)C0 and earlier 2.90(AAHJ.2)C0
GS1900-24 2.90(AAHL.1)C0 and earlier 2.90(AAHL.2)C0
GS1900-24E 2.90(AAHK.1)C0 and earlier 2.90(AAHK.2)C0
GS1900-24EP 2.90(ABTO.1)C0 and earlier 2.90(ABTO.2)C0
GS1900-24HPv2 2.90(ABTP.1)C0 and earlier 2.90(ABTP.2)C0
GS1900-48 2.90(AAHN.1)C0 and earlier 2.90(AAHN.2)C0
GS1900-48HPv2 2.90(ABTQ.1)C0 and earlier 2.90(ABTQ.2)C0

Zyxel states that on-market products not listed in the table are unaffected. The NVD record is marked Deferred, so the vendor table is the authoritative version reference.

Counting candidate devices

ZoomEye returns 5,920 matches for app="Zyxel" && title="GS1900". The query matches Zyxel devices whose HTML title contains the GS1900 family name. That count is an inventory signal, not a vulnerability confirmation, and it does not describe reachability. A CVE-scoped query, vul.cve="CVE-2026-7273", returned no indexed assets.
The reachability question has to be answered inside the network: which VLANs can reach the switch's management address, and which of those VLANs carry devices that should not have that access.

Reducing exposure

Patch the affected models using the fixed builds in the table. That is the only change that removes the vulnerability.
Segmentation reduces the attack surface in the meantime, and it stays useful afterwards. Put switch management on a dedicated VLAN that carries no user traffic, and apply ACLs so client, guest, and IoT segments cannot reach it. Disable remote management on interfaces that are reachable from those segments. Where an out-of-band management path exists, use it for administrative access instead of the in-band interface.
These controls do not repair the overflow. They remove the network position the exploit needs, which is the same position an attacker would use for other management-plane attacks.

Verification

After applying either the patch or the segmentation changes, confirm the result rather than assuming it. From a client segment, attempt to reach the switch's web interface and confirm the connection fails. From the management VLAN, confirm administrative access still works. Record the firmware version on each device so the next advisory can be matched against the estate quickly.

References

Top comments (0)