---
schema: 1
kind: vulnerability
title: "CVE-2026-7273 — Zyxel GS1900 switches: pre-auth stack overflow reaches CISA KEV after GreyNoise catches an actor overlapping Red Heron exfiltrating configs and hashed root credentials from 996 devices in 48 countries"
headline: "CISA adds a pre-auth Zyxel switch RCE to KEV after GreyNoise catches a Red Heron-linked actor exploiting it at scale"
summary: >
  CVE-2026-7273 (CVSS 8.8) is a pre-auth stack-based buffer overflow in the CGI login
  handler of Zyxel GS1900 series switches, patched in June 2026 and added to CISA KEV
  on 2026-09-21 after GreyNoise found an actor it assesses is the same as or related to
  Red Heron exploiting it on or about 17 August 2026, exfiltrating configuration data,
  network information and hashed root credentials from 996 switches in 48 countries —
  57% of them still on factory-default credentials. The same actor separately ran a
  WordPress exploitation chain that stole over 18,000 government records and shows
  signs of LLM-assisted tooling.
discovered_at: "2026-09-22T04:32:00Z"
updated_at: null
event_date: "2026-09-21"
run_id: 2026-09-22T0410Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, rce, pre-auth, actively-exploited, cisa-kev]
regions: [global]
sectors: [public-sector]
entities: [actor:red-heron, product:zyxel-gs1900-series-switches]
techniques: [T1190, T1105, T1059.004, T1005]
affected_products: ["Zyxel GS1900 Series Switches"]
cves:
  - id: CVE-2026-7273
    cvss: "8.8"
    epss: "0.00315"
    type: rce
    vector: zero-click
    auth: pre-auth
    status: [exploited, cisa-kev, patch-available]
    affected: "GS1900-8/-8HP/-10HP/-16/-24/-24E/-24EP/-24HPv2/-48/-48HPv2, each at or below its own \"…(x).1C0\" baseline build"
    fixed: "each model's own \"…(x).2C0\" build (per-model builds differ; see Zyxel's advisory table)"
sources:
  - url: "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026"
    publisher: "Zyxel PSIRT"
    date: "2026-06-16"
    role: primary
  - url: "https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitation"
    publisher: "GreyNoise"
    date: "2026-09-21"
    role: primary
  - url: "https://www.cisa.gov/news-events/alerts/2026/09/21/cisa-adds-one-known-exploited-vulnerability-catalog"
    publisher: "CISA"
    date: "2026-09-21"
    role: corroborating
  - url: "https://www.acronis.com/en/tru/posts/red-heron-exploits-gitea-n-day-flaw-in-multinational-campaign-exposing-new-linux-rootkit/"
    publisher: "Acronis Threat Research Unit"
    date: "2026-09-13"
    role: corroborating
closed_sources: []
evidence:
  - quote: "A stack-based buffer overflow vulnerability in the CGI program of the Zyxel GS1900 series switch firmware could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request."
    publisher: "Zyxel PSIRT"
  - quote: "The MCA successfully exploited and exfiltrated sensitive data from 996 ZyXEL switches across 48 countries."
    publisher: "GreyNoise"
  - quote: "While the credentials were hashed, 564 of the victims had factory default credentials."
    publisher: "GreyNoise"
  - quote: "The adversary is the same or related to “Red Heron” reported on by Acronis based on use of the same command and control (C2) domain, malware family, exploitation of Gitea in July, and other tactics, techniques, and procedures (TTPs)."
    publisher: "GreyNoise"
verification: multi-source
sourcing_note: "Actor attribution is GreyNoise's own hedged assessment (\"same or related to\" Red Heron); Zyxel and CISA corroborate the vulnerability and exploitation status but do not comment on attribution."
confidence: high
references: []
deep_dive: true
deep_dive_category: network-stack-rce
org_triage: null
classification:
  reliability: B
  credibility: 1
watchlist_hit: false
actions:
  - "Patch every deployed Zyxel GS1900 switch to its per-model fixed \"…(x).2C0\" build now, and audit and rotate any switch still on its factory-default admin credentials — GreyNoise found 564 of 996 exploited switches (57%) had never had theirs changed, which lets the actor re-enter even after the hashed credential set is rotated."
updates: []
migrated_from: null
---

CVE-2026-7273 is a stack-based buffer overflow in the CGI program of Zyxel GS1900 series smart-managed switch firmware that lets a LAN-based, unauthenticated attacker execute OS commands via a crafted HTTP request to the switch's web-management interface ([Zyxel PSIRT, 2026-06-16](https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026)). Zyxel patched all ten affected models — GS1900-8, -8HP, -10HP, -16, -24, -24E, -24EP, -24HPv2, -48 and -48HPv2 — on 2026-06-16, each at its own "…(x).2C0" build one increment above the vulnerable "…(x).1C0 and earlier" baseline ([Zyxel PSIRT, 2026-06-16](https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026)). CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2026-09-21, acting on GreyNoise sensor-grid research published the same day: GreyNoise has tracked a single malicious cyber actor since 7 May 2026, a suspected Chinese speaker possibly working in UTC+8 based on Chinese-language code comments and operational timing, that it assesses is the same as or related to Red Heron, a Chinese-speaking, PRC-linked cluster Acronis Threat Research Unit profiled on 2026-09-13 for rapid n-day weaponisation of a Gitea flaw ([Acronis Threat Research Unit, 2026-09-13](https://www.acronis.com/en/tru/posts/red-heron-exploits-gitea-n-day-flaw-in-multinational-campaign-exposing-new-linux-rootkit/)), based on a shared command-and-control domain, malware family and other overlapping tradecraft ([GreyNoise, 2026-09-21](https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitation)).

On or about 17 August 2026 the actor exploited CVE-2026-7273 with a PyArmor-6.7.5-obfuscated Python tool offering two modes: a deterministic single-request GOT-overwrite, and an ASLR-brute-force stack mode averaging roughly 2,048 attempts, explicitly targeting firmware versions 2.10-2.90 of the GS1900-24, while also providing command-line options for the target's libc base address and GOT offsets that GreyNoise states could be used to target other firmware in scope for the vulnerability ([GreyNoise, 2026-09-21](https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitation)). The actor exfiltrated configuration data, networking information and hashed root-level credentials from 996 Zyxel GS1900 switches across 48 countries, making the switch's on-device shell fetch a TFTP-delivered collector script and stage the harvested data to a file on the switch for retrieval ([GreyNoise, 2026-09-21](https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitation)). "While the credentials were hashed, 564 of the victims had factory default credentials" ([GreyNoise, 2026-09-21](https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitation)) — for the majority of victims the exfiltrated hash was unnecessary, since the unrotated default password alone gave the actor durable re-entry.

GreyNoise frames the Zyxel exploitation as one prong of a broader, opportunistic operation: the same actor separately exploited an already-KEV-listed Ubiquiti UniFi OS chain and ran a WordPress exploit chain that compromised at least 49 organizations in 29 countries from 20 July onward, with the worst confirmed case, an unnamed Western government, losing over 18,000 sensitive database records ([GreyNoise, 2026-09-21](https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitation)). GreyNoise's forensic timeline of that intrusion shows post-exploitation tooling — near-duplicate privilege-escalation script variants with only superficial changes between iterations, and heavy inline Chinese-language commentary explaining each attempted technique — that it assesses bears the hallmarks of LLM-assisted code generation, though no specific AI tool was identified in use ([GreyNoise, 2026-09-21](https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitation)).

**Detection:** the flaw requires a "LAN-based" attacker per Zyxel's own advisory ([Zyxel PSIRT, 2026-06-16](https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026)), meaning the CGI endpoint is reachable only from a host already on the switch's management-interface network segment, not directly from the internet by default; the 57% factory-default-credential rate among confirmed victims suggests many deployments put the web-management UI on a flat or trusted VLAN reachable from any already-compromised host, or expose it via NAT/port-forwarding for remote administration. An outbound TFTP request (UDP/69, or a non-standard high port, as observed here) originating from a network switch's own management IP is a strong hunt signal, as is the switch's on-device shell invoking a shell interpreter against a file just retrieved via TFTP. Because the exfiltration itself leaves no persistent artifact on the switch, treat any GS1900 that was reachable and unpatched between 2026-06-16 and its patch date as a candidate for a compromise assessment centred on credential rotation rather than malware removal.

**Defender takeaway:** patch every GS1900 switch to its per-model fixed build now; move switch management interfaces onto a dedicated out-of-band management VLAN with ACLs denying general-LAN access to the web-admin/CGI port; rotate any credential that may have shipped as factory-default on a GS1900 switch, regardless of patch status.
