[CIVN-2026-0319] Buffer overflow vulnerability in Zyxel

By Published On: June 18, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Buffer overflow vulnerability in Zyxel


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


Zyxel GS1900-8 version 2.90(AAHH.1)C0 and earlier

Zyxel GS1900-8HP version 2.90(AAHI.1)C0 and earlier

Zyxel GS1900-10HP version 2.90(AAZI.1)C0 and earlier

Zyxel GS1900-16 version 2.90(AAHJ.1)C0 and earlier

Zyxel GS1900-24 version 2.90(AAHL.1)C0 and earlier

Zyxel GS1900-24E version 2.90(AAHK.1)C0 and earlier

Zyxel GS1900-24EP version 2.90(ABTO.1)C0 and earlier

Zyxel GS1900-24HPv2 version 2.90(ABTP.1)C0 and earlier

Zyxel GS1900-48 version 2.90(AAHN.1)C0 and earlier

Zyxel GS1900-48HPv2 version 2.90(ABTQ.1)C0 and earlier

Overview


Buffer overflow vulnerability has been reported in Zyxel which could allow an attacker to execute arbitrary operating system commands on the targeted system.


Target Audience:

All end-user organizations and individuals using Zyxel.


Risk Assessment:

High risk of remote code execution.


Impact Assessment:

Potential for remote code execution.


Description


Zyxel is a networking equipment manufacturer that provides switches, routers, firewalls, wireless access points, and other network infrastructure solutions for businesses and consumers.


A vulnerability has been reported in Zyxel Communications GS1900 series switches due to a stack-based buffer overflow vulnerability in the CGI program of the switch firmware. A LAN-based, unauthenticated attacker could exploit this vulnerability to send specially crafted HTTP requests to vulnerable devices and potentially execute OS commands on the targeted system.


Successful exploitation of this vulnerability could allow an attacker to execute arbitrary operating system commands on the targeted system.


Solution


Apply appropriate updates as mentioned by the vendor:

https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026



Vendor Information


Zyxel

https://www.zyxel.com/


References


 

https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026


CVE Name

CVE-2026-7273




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmo0DQcACgkQ3jCgcSdc

ys/vfA/+NUW70R/I+hv2IrkFFUdDeB0ceXd9gHS8DnAaxBP6OsNMwlNvJMuflBzm

s2YtOHZHIvJcTCvaKSd4xtJ9ly7AHZ6kEuZSpMOKKnLZ06CVJR8T7YiF9HwAsdc7

EPGkRt2o/h6nXOZWADJTgghlZnItPSHDg39ZDaHLOYYqvaBOSU/bekWWehCULLyK

g41kv6j25TRjPF/yMVN1uJ4JwG8u+vEoD9HlWNuO4+n7BZv+T7Rx3M0BwCIqu5Kq

i9JXT+K84pT6HvqyC2oTDjq4mtAD6W3VVWpQ9DQz0Ebf47BUHx7DWf+4OnXSVVL8

iQjY1xw7DQSEC6ViiwfkQz3tjtwsmDyZ04t4q99dXhN2vdCK56L4qiRtkAPjDwIr

4rzyERexpGH8Eh1KMAVRciHzkNF+/WHvYvbZPa0Dh9x2ThBN+lKGYfb1ZFl01VI/

KfKuUrqebC8oVF9XF80aOMaR9gsi+rh1/2XycbPhLW1UBWBe1rF4D4ZXUOiPgoiz

N7VmJu13APqMuwo24JLifvUtchb4PMvSmW7rd4X0/8/FxVinTbBHCy4xIkMcXXko

dOeUzEKCniIaEAU6zaLrZNCOLRUgXVktZ4QHBApRZkO3rbDD+FuD65Wf/3jtN30s

bVQLaXTWFNgqEF0w0NitckUdfiweJHwh4Ulhn0BXNUsa9RiI+MU=

=PnHc

—–END PGP SIGNATURE—–

Share this article