CTIPilot

Zyxel GS1900 Series Switches stack-based buffer overflow, exploited at scale by an actor GreyNoise assesses overlaps Red Heron, CISA KEV

cve · CVE-2026-7273

Coverage timeline
1
first 2026-09-22 → last 2026-09-22
Peak priority
high
1 high
Sources cited
4
4 hosts
Sections touched
1
deep-dive
Co-occurring entities
2
see Co-occurring entities below
ATT&CK techniques
4
pinned v19.2 · see below

ATT&CK techniques

4 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-22/cve-2026-7273-zyxel-gs1900-red-heron-kev-exploited · ATT&CK page ↗

Execution TA0002

T1059.004Command and Scripting Interpreter: Unix Shell×1

Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.

Evidence: 2026-09-22/cve-2026-7273-zyxel-gs1900-red-heron-kev-exploited · ATT&CK page ↗

Collection TA0009

T1005Data from Local System×1

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.

Evidence: 2026-09-22/cve-2026-7273-zyxel-gs1900-red-heron-kev-exploited · ATT&CK page ↗

Command and Control TA0011

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-09-22/cve-2026-7273-zyxel-gs1900-red-heron-kev-exploited · ATT&CK page ↗

Story timeline

  1. 2026-09-22CVE-2026-7273, Zyxel GS1900 switches: pre-auth stack overflow reaches CISA KEV after GreyNoise catches an actor overlapping Red Heron exfiltrating configs and hashed root credentials from 996 devices in 48 countries
    deep-diveCISA adds a pre-auth Zyxel switch RCE to KEV after GreyNoise catches a Red Heron-linked actor exploiting it at scale

Where this entity is cited

  • deep-dive1

Source distribution

  • acronis.com1 (25%)
  • cisa.gov1 (25%)
  • greynoise.io1 (25%)
  • zyxel.com1 (25%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Zyxel GS1900 Series Switches stack-based buffer overflow, exploited at scale by an actor GreyNoise assesses overlaps Red Heron, CISA KEV (1)

2026-09-22 · view entry permalink →

HIGHCVE-2026-7273exploitedNATOB1

CVE-2026-7273, Zyxel GS1900 switches: pre-auth stack overflow reaches CISA KEV after GreyNoise catches an actor overlapping Red Heron exfiltrating configs and hashed root credentials from 996 devices in 48 countries

CVE-2026-7273 is a stack-based buffer overflow in the CGI program of Zyxel GS1900 series smart-managed switch firmware that lets a LAN-based, unauthenticated attacker execute OS commands via a crafted HTTP request to the switch's web-management interface (Zyxel PSIRT, 2026-06-16). Zyxel patched all ten affected models (GS1900-8, -8HP, -10HP, -16, -24, -24E, -24EP, -24HPv2, -48 and -48HPv2) on 2026-06-16, each at its own "…(x).2C0" build one increment above the vulnerable "…(x).1C0 and earlier" baseline (Zyxel PSIRT, 2026-06-16). CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2026-09-21, acting on GreyNoise sensor-grid research published the same day: GreyNoise has tracked a single malicious cyber actor since 7 May 2026, a suspected Chinese speaker possibly working in UTC+8 based on Chinese-language code comments and operational timing, that it assesses is the same as or related to Red Heron, a Chinese-speaking, PRC-linked cluster Acronis Threat Research Unit profiled on 2026-09-13 for rapid n-day weaponisation of a Gitea flaw (Acronis Threat Research Unit, 2026-09-13), based on a shared command-and-control domain, malware family and other overlapping tradecraft (GreyNoise, 2026-09-21).

On or about 17 August 2026 the actor exploited CVE-2026-7273 with a PyArmor-6.7.5-obfuscated Python tool offering two modes: a deterministic single-request GOT-overwrite, and an ASLR-brute-force stack mode averaging roughly 2,048 attempts, explicitly targeting firmware versions 2.10-2.90 of the GS1900-24, while also providing command-line options for the target's libc base address and GOT offsets that GreyNoise states could be used to target other firmware in scope for the vulnerability (GreyNoise, 2026-09-21). The actor exfiltrated configuration data, networking information and hashed root-level credentials from 996 Zyxel GS1900 switches across 48 countries, making the switch's on-device shell fetch a TFTP-delivered collector script and stage the harvested data to a file on the switch for retrieval (GreyNoise, 2026-09-21). "While the credentials were hashed, 564 of the victims had factory default credentials" (GreyNoise, 2026-09-21), for the majority of victims the exfiltrated hash was unnecessary, since the unrotated default password alone gave the actor durable re-entry.

GreyNoise frames the Zyxel exploitation as one prong of a broader, opportunistic operation: the same actor separately exploited an already-KEV-listed Ubiquiti UniFi OS chain and ran a WordPress exploit chain that compromised at least 49 organizations in 29 countries from 20 July onward, with the worst confirmed case, an unnamed Western government, losing over 18,000 sensitive database records (GreyNoise, 2026-09-21). GreyNoise's forensic timeline of that intrusion shows post-exploitation tooling (near-duplicate privilege-escalation script variants with only superficial changes between iterations, and heavy inline Chinese-language commentary explaining each attempted technique) that it assesses bears the hallmarks of LLM-assisted code generation, though no specific AI tool was identified in use (GreyNoise, 2026-09-21).

A stack-based buffer overflow vulnerability in the CGI program of the Zyxel GS1900 series switch firmware could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

Zyxel PSIRT 2026-06-16

The MCA successfully exploited and exfiltrated sensitive data from 996 ZyXEL switches across 48 countries.

While the credentials were hashed, 564 of the victims had factory default credentials.

The adversary is the same or related to “Red Heron” reported on by Acronis based on use of the same command and control (C2) domain, malware family, exploitation of Gitea in July, and other tactics, techniques, and procedures (TTPs).

GreyNoise 2026-09-21
vulnerability22 Sep 04:32Zmulti-sourceOpen finding ↗