CVE-2026-7273
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
- Published Jun 16, 2026
- CVSS 8.8 high
- 2.5% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- Public exploit code is available
Affected software
In the news
- Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access The Hacker News ·
- CISA Adds One Known Exploited Vulnerability to Catalog CISA ·
- Zyxel security advisory (AV26-603) – Update 1 Canadian Centre for Cyber Security ·