
[CIVN-2026-0319] Buffer overflow vulnerability in Zyxel
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Buffer overflow vulnerability in Zyxel
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Zyxel GS1900-8 version 2.90(AAHH.1)C0 and earlier
Zyxel GS1900-8HP version 2.90(AAHI.1)C0 and earlier
Zyxel GS1900-10HP version 2.90(AAZI.1)C0 and earlier
Zyxel GS1900-16 version 2.90(AAHJ.1)C0 and earlier
Zyxel GS1900-24 version 2.90(AAHL.1)C0 and earlier
Zyxel GS1900-24E version 2.90(AAHK.1)C0 and earlier
Zyxel GS1900-24EP version 2.90(ABTO.1)C0 and earlier
Zyxel GS1900-24HPv2 version 2.90(ABTP.1)C0 and earlier
Zyxel GS1900-48 version 2.90(AAHN.1)C0 and earlier
Zyxel GS1900-48HPv2 version 2.90(ABTQ.1)C0 and earlier
Overview
Buffer overflow vulnerability has been reported in Zyxel which could allow an attacker to execute arbitrary operating system commands on the targeted system.
Target Audience:
All end-user organizations and individuals using Zyxel.
Risk Assessment:
High risk of remote code execution.
Impact Assessment:
Potential for remote code execution.
Description
Zyxel is a networking equipment manufacturer that provides switches, routers, firewalls, wireless access points, and other network infrastructure solutions for businesses and consumers.
A vulnerability has been reported in Zyxel Communications GS1900 series switches due to a stack-based buffer overflow vulnerability in the CGI program of the switch firmware. A LAN-based, unauthenticated attacker could exploit this vulnerability to send specially crafted HTTP requests to vulnerable devices and potentially execute OS commands on the targeted system.
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary operating system commands on the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026
Vendor Information
Zyxel
https://www.zyxel.com/
References
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026
CVE Name
CVE-2026-7273
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmo0DQcACgkQ3jCgcSdc
ys/vfA/+NUW70R/I+hv2IrkFFUdDeB0ceXd9gHS8DnAaxBP6OsNMwlNvJMuflBzm
s2YtOHZHIvJcTCvaKSd4xtJ9ly7AHZ6kEuZSpMOKKnLZ06CVJR8T7YiF9HwAsdc7
EPGkRt2o/h6nXOZWADJTgghlZnItPSHDg39ZDaHLOYYqvaBOSU/bekWWehCULLyK
g41kv6j25TRjPF/yMVN1uJ4JwG8u+vEoD9HlWNuO4+n7BZv+T7Rx3M0BwCIqu5Kq
i9JXT+K84pT6HvqyC2oTDjq4mtAD6W3VVWpQ9DQz0Ebf47BUHx7DWf+4OnXSVVL8
iQjY1xw7DQSEC6ViiwfkQz3tjtwsmDyZ04t4q99dXhN2vdCK56L4qiRtkAPjDwIr
4rzyERexpGH8Eh1KMAVRciHzkNF+/WHvYvbZPa0Dh9x2ThBN+lKGYfb1ZFl01VI/
KfKuUrqebC8oVF9XF80aOMaR9gsi+rh1/2XycbPhLW1UBWBe1rF4D4ZXUOiPgoiz
N7VmJu13APqMuwo24JLifvUtchb4PMvSmW7rd4X0/8/FxVinTbBHCy4xIkMcXXko
dOeUzEKCniIaEAU6zaLrZNCOLRUgXVktZ4QHBApRZkO3rbDD+FuD65Wf/3jtN30s
bVQLaXTWFNgqEF0w0NitckUdfiweJHwh4Ulhn0BXNUsa9RiI+MU=
=PnHc
—–END PGP SIGNATURE—–


