## Overview
CISA has added CVE-2026-7273 to its Known Exploited Vulnerabilities (KEV) list. This vulnerability affects the Zyxel GS1900 Series Switches, specifically the GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0. The addition to the KEV list indicates a federal deadline for remediation. Evidence suggests that the vulnerability is actively being exploited.
## Technical Details
The vulnerability is a stack-based buffer overflow located in the CGI program of the affected firmware. An attacker on the local area network (LAN) can exploit this flaw without authentication. By sending a specially crafted HTTP request, the attacker can potentially execute arbitrary OS commands on the device. The CVSS score of 8.8 indicates a high severity level, emphasizing the need for immediate action.
## Impact
Successful exploitation of this vulnerability could lead to unauthorized access and control over the affected switches. This could result in data breaches, network disruptions, or the deployment of further malicious payloads within the network. Organizations using the affected Zyxel switches should be aware of the potential risks associated with this vulnerability.
## Mitigation
Defenders should immediately update the firmware of the Zyxel GS1900-48HPv2 to the latest version to close this vulnerability. Regularly check for updates from Zyxel and apply patches as they become available. Additionally, restrict access to the management interface of the switches to trusted IP addresses only. Implementing network segmentation can further reduce the risk of exploitation.
CSURFACE Threat Sensor