> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog

[SOURCE] Security Affairs [AUTHOR: Pierluigi Paganini] [DATE: 22/09/2026 09:13] [LANGUAGE: EN]
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Zyxel GS1900 Series Switches flaw, tracked as CVE-2026-7273 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is a stack-based buffer overflow that could allow attackers to execute arbitrary operating system commands. “A stack-based buffer overflow vulnerability in the CGI program of the Zyxel GS1900 series switch firmware could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.” reads the advisory. The vulnerability affects the CGI component of Zyxel’s GS1900 switch firmware. According to Zyxel, an unauthenticated attacker on the local network could exploit the flaw by sending a specially crafted HTTP request and potentially gain the ability to run OS commands on the device. The vulnerability has been fixed in the following firmware versions: Affected modelAffected versionPatch availabilityGS1900-82.90(AAHH.1)C0 and earlier2.90(AAHH.2)C0GS1900-8HP2.90(AAHI.1)C0 and earlier2.90(AAHI.2)C0GS1900-10HP2.90(AAZI.1)C0 and earlier2.90(AAZI.2)C0GS1900-162.90(AAHJ.1)C0 and earlier2.90(AAHJ.2)C0GS1900-242.90(AAHL.1)C0 and earlier2.90(AAHL.2)C0GS1900-24E2.90(AAHK.1)C0 and earlier2.90(AAHK.2)C0GS1900-24EP2.90(ABTO.1)C0 and earlier2.90(ABTO.2)C0GS1900-24HPv22.90(ABTP.1)C0 and earlier2.90(ABTP.2)C0GS1900-482.90(AAHN.1)C0 and earlier2.90(AAHN.2)C0GS1900-48HPv22.90(ABTQ.1)C0 and earlier2.90(ABTQ.2)C0 CISA did not disclose technical details about the attacks exploiting this issue or who is behind them. Zyxel credited Lei Gu, Jun Cao, Zhiqing Rui, Jingzheng Wu, and Tianyue Luo from ISCAS with finding and reporting the flaw. At the time of writing, Zyxel had not updated its advisory to confirm whether the vulnerability was being actively exploited. According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog. Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure. CISA orders federal agencies to fix the flaw by September 24, 2026. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, CISA)
[messages.read_original_source] →