Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability

Release Date: 21st September 2026 (Added 22 September 2026)

Impact : HIGH

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-7273 is a high-severity stack-based buffer overflow vulnerability (CWE-121) in the CGI program of Zyxel GS1900 series managed switches. The flaw allows a LAN-based, unauthenticated attacker to send a crafted HTTP request and potentially execute arbitrary OS commands on the affected device.

Reference

  1. https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026
  2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  3. https://nvd.nist.gov/vuln/detail/cve-2026-7273