Zyxel GS1900-48HPv2 2.90(ABTQ.1)C0 Buffer Overflow in CGI Program
CVE-2026-7273 Published on June 16, 2026

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

Vendor Advisory NVD

Known Exploited Vulnerability

This Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

The following remediation steps are recommended / required by September 24, 2026: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicab

Vulnerability Analysis

Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

What is a Stack Overflow Vulnerability?

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

CVE-2026-7273 has been classified to as a Stack Overflow vulnerability or weakness.


Affected Versions

Zyxel GS1900-48HPv2 firmware: Zyxel GS1900-8 firmware: Zyxel GS1900-8HP firmware: Zyxel GS1900-10HP firmware: Zyxel GS1900-16 firmware: Zyxel GS1900-24 firmware: Zyxel GS1900-24E firmware: Zyxel GS1900-24EP firmware: Zyxel GS1900-24HPv2 firmware: Zyxel GS1900-48 firmware:

Exploit Probability

EPSS
0.28%
Percentile
19.26%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.