2026-09-22 · view entry permalink →
CVE-2026-7273, Zyxel GS1900 switches: pre-auth stack overflow reaches CISA KEV after GreyNoise catches an actor overlapping Red Heron exfiltrating configs and hashed root credentials from 996 devices in 48 countries
CVE-2026-7273 is a stack-based buffer overflow in the CGI program of Zyxel GS1900 series smart-managed switch firmware that lets a LAN-based, unauthenticated attacker execute OS commands via a crafted HTTP request to the switch's web-management interface (Zyxel PSIRT, 2026-06-16). Zyxel patched all ten affected models (GS1900-8, -8HP, -10HP, -16, -24, -24E, -24EP, -24HPv2, -48 and -48HPv2) on 2026-06-16, each at its own "…(x).2C0" build one increment above the vulnerable "…(x).1C0 and earlier" baseline (Zyxel PSIRT, 2026-06-16). CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2026-09-21, acting on GreyNoise sensor-grid research published the same day: GreyNoise has tracked a single malicious cyber actor since 7 May 2026, a suspected Chinese speaker possibly working in UTC+8 based on Chinese-language code comments and operational timing, that it assesses is the same as or related to Red Heron, a Chinese-speaking, PRC-linked cluster Acronis Threat Research Unit profiled on 2026-09-13 for rapid n-day weaponisation of a Gitea flaw (Acronis Threat Research Unit, 2026-09-13), based on a shared command-and-control domain, malware family and other overlapping tradecraft (GreyNoise, 2026-09-21).
On or about 17 August 2026 the actor exploited CVE-2026-7273 with a PyArmor-6.7.5-obfuscated Python tool offering two modes: a deterministic single-request GOT-overwrite, and an ASLR-brute-force stack mode averaging roughly 2,048 attempts, explicitly targeting firmware versions 2.10-2.90 of the GS1900-24, while also providing command-line options for the target's libc base address and GOT offsets that GreyNoise states could be used to target other firmware in scope for the vulnerability (GreyNoise, 2026-09-21). The actor exfiltrated configuration data, networking information and hashed root-level credentials from 996 Zyxel GS1900 switches across 48 countries, making the switch's on-device shell fetch a TFTP-delivered collector script and stage the harvested data to a file on the switch for retrieval (GreyNoise, 2026-09-21). "While the credentials were hashed, 564 of the victims had factory default credentials" (GreyNoise, 2026-09-21), for the majority of victims the exfiltrated hash was unnecessary, since the unrotated default password alone gave the actor durable re-entry.
GreyNoise frames the Zyxel exploitation as one prong of a broader, opportunistic operation: the same actor separately exploited an already-KEV-listed Ubiquiti UniFi OS chain and ran a WordPress exploit chain that compromised at least 49 organizations in 29 countries from 20 July onward, with the worst confirmed case, an unnamed Western government, losing over 18,000 sensitive database records (GreyNoise, 2026-09-21). GreyNoise's forensic timeline of that intrusion shows post-exploitation tooling (near-duplicate privilege-escalation script variants with only superficial changes between iterations, and heavy inline Chinese-language commentary explaining each attempted technique) that it assesses bears the hallmarks of LLM-assisted code generation, though no specific AI tool was identified in use (GreyNoise, 2026-09-21).
A stack-based buffer overflow vulnerability in the CGI program of the Zyxel GS1900 series switch firmware could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
The MCA successfully exploited and exfiltrated sensitive data from 996 ZyXEL switches across 48 countries.
While the credentials were hashed, 564 of the victims had factory default credentials.
The adversary is the same or related to “Red Heron” reported on by Acronis based on use of the same command and control (C2) domain, malware family, exploitation of Gitea in July, and other tactics, techniques, and procedures (TTPs).