U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog
Brief
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog.
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added a Zyxel GS1900 Series Switches flaw, tracked as CVE-2026-7273 (CVSS score of 8. 8), to its Known Exploited Vulnerabilities (KEV) catalog .
The flaw is a stack-based buffer overflow that could allow attackers to execute arbitrary operating system commands.
“A stack-based buffer overflow vulnerability in the CGI program of the Zyxel GS1900 series switch firmware could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.” reads the advisory .
The vulnerability affects the CGI component of Zyxel’s GS1900 switch firmware.
