Daily Top · Vulnerabilities / Network

CISA put Zyxel GS1900 on KEV. GreyNoise already counted 996 switches in 48 countries.

CVE-2026-7273 is unauthenticated OS command execution on the CGI. Vendor scored it LAN. Patch firmware, then hunt default admin. Federal due date is Thursday.

RWP Ventures · 2026-09-22 · event 2026-09-21 · 13 min read · priority 8.5

Bottom line up front

CONFIRMED CISA added CVE-2026-7273 to the Known Exploited Vulnerabilities catalog on 21 September 2026. Catalog version 2026.09.21 (released 21 September 18:46 UTC, count 1717). It is the only new row since the [Linux kernel trio](/posts/2026-09-19-linux-kernel-kev-ktls-ebtables-afalg/) on 18 September. Federal due date is 24 September 2026. Ransomware-campaign use is Unknown. Forensic triage is Yes.

The product is the Zyxel GS1900 smart-managed Gigabit access-switch family. The bug is a stack-based buffer overflow in the CGI program (CWE-121). Zyxel’s June advisory, which CISA still cites, says a LAN-based, unauthenticated attacker can send a crafted HTTP request and potentially execute OS commands. Zyxel’s CNA score is 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. NVD has not published its own vector. Firmware that closes it shipped 16 June 2026. As of this morning Zyxel has not revised the advisory to say the bug is exploited.

Do not collapse three facts.

  1. Adjacent is not “safe.” AV:A means the attacker needs a path to the management CGI. GreyNoise’s count is what you get when that CGI is on the internet, on a VPN that is not the LAN you think it is, or on a guest/IoT VLAN the operator never treated as hostile.
  2. The victim set is already measured. GreyNoise (Andrew Thompson, Mark Mager, 21 September) reported a suspected Chinese-speaking malicious cyber actor that exploited GS1900 units on or about 17 August 2026 and exfiltrated configurations, hashed root credentials, and network information from 996 switches in 48 countries. That is the first public in-the-wild write-up of this CVE. CISA’s KEV row is the federal confirmation; it does not name the campaign.
  3. Patching without asking who still has admin is incomplete. GreyNoise: 564 of those 996 still had factory-default credentials. Hashed root is not the same as a unique password.

This is not a re-run of [yesterday’s Jade Sleet Daily Top](/posts/2026-09-21-jade-sleet-it-services-flatroof-roofdeck/). Different product, different clock, different access class.

FactRecord
CVECVE-2026-7273
ProductZyxel GS1900 series (8/10/16/24/48-port smart-managed, including PoE SKUs)
KEV catalog2026.09.21, count 1717
Added / due21 September / 24 September 2026
Vendor patch16 June 2026, 2.90(*.2)C0 per model
ExploitationCONFIRMED as KEV; GreyNoise campaign CONFIRMED as their telemetry
Ransomware useUnknown
Named CISA actorNone
OT / process impactNone claimed

What happened

Zyxel published the CGI overflow on 16 June 2026 and credited Lei Gu, Jun Cao, Zhiqing Rui, Jingzheng Wu, and Tianyue Luo of ISCAS. The June text is still the vendor record: overflow in the CGI, LAN, no authentication, crafted HTTP, potential OS command execution. Patches are the 2.90(….2)C0 builds. Zyxel’s table (and the BleepingComputer reprint this morning):

Affected modelAffected versionFixed version
GS1900-82.90(AAHH.1)C0 and earlier2.90(AAHH.2)C0
GS1900-8HP2.90(AAHI.1)C0 and earlier2.90(AAHI.2)C0
GS1900-10HP2.90(AAZI.1)C0 and earlier2.90(AAZI.2)C0
GS1900-162.90(AAHJ.1)C0 and earlier2.90(AAHJ.2)C0
GS1900-242.90(AAHL.1)C0 and earlier2.90(AAHL.2)C0
GS1900-24E2.90(AAHK.1)C0 and earlier2.90(AAHK.2)C0
GS1900-24EP2.90(ABTO.1)C0 and earlier2.90(ABTO.2)C0
GS1900-24HPv22.90(ABTP.1)C0 and earlier2.90(ABTP.2)C0
GS1900-482.90(AAHN.1)C0 and earlier2.90(AAHN.2)C0
GS1900-48HPv22.90(ABTQ.1)C0 and earlier2.90(ABTQ.2)C0

Zyxel’s June note: on-market products not in that table remain unaffected. Do not inventory “every Zyxel switch.” Do inventory every GS1900 still on 2.90(*.1) or earlier.

CISA’s 21 September alert names this one CVE. The JSON row matches: vendor Zyxel, product GS1900 Series Switches, CWE-121, notes point at the June advisory, BOD 26-04, and the forensics-triage guidance. This is Zyxel’s 13th KEV CVE. The previous twelve are older CPE, firewall, NAS, and router rows, not this switch family.

GreyNoise’s 21 September report is the public exploitation narrative CISA did not write. Timeline they published:

WhenWhatStatus
16 Jun 2026Zyxel advisory and patchesCONFIRMED vendor
~17 Aug 2026MCA exploits GS1900, pulls a collector over TFTP, stages lootCONFIRMED GreyNoise
17 Sep 2026GreyNoise: first public in-wild case; not yet KEVCONFIRMED their statement at publication
21 Sep 2026GreyNoise blog; CISA KEV 2026.09.21CONFIRMED
22 Sep 2026BleepingComputer / The Hacker News English amplificationCONFIRMED secondary
24 Sep 2026FCEB due dateCONFIRMED catalog

Post-exploit, as GreyNoise reconstructed it from the actor’s tooling: a TFTP get of a collector script, then a copy of gathered data to a web-reachable path on the switch (/home/web/tmp/info.txt). RWP is not republishing the exploit script, the PyArmor wrapper, or the command-line flags. Defenders need the collection behavior, not a reproduction.

Country counts GreyNoise published (top of 996): Italy 133, United States 129, Taiwan 123, France 90, South Korea 69, Netherlands 66, Czech Republic 49, United Kingdom 33. The long tail runs to 48 countries. Treat those as GreyNoise’s victim geography, not a CISA attribution.

Why it matters

GS1900 is the cheap managed access layer in branches, clinics, warehouses, schools, and a lot of plants that never bought a Cisco Catalyst. PoE SKUs sit under cameras, phones, and APs. A switch that will run OS commands is a place to read configs, persist a credential, alter VLANs, or cut PoE. That is network-plane impact. It is not, on this evidence, a PLC or a process.

The CVSS vector is the operational trap. Teams that file AV:A under “needs to be on the LAN” will skip internet-exposed management, cellular-backed cameras on the same L2, and MSP jump hosts. GreyNoise’s 996 is the counter-example. The right question is “can an unauthenticated HTTP client reach the CGI,” not “does NVD say adjacent.”

The default-credential slice is the second trap. More than half of the collected switches still had factory defaults. Firmware without a unique admin password is a second, independent finding. BOD 26-04’s forensic-triage language applies before you declare the patch the closure.

KEV on a three-day clock, after a June patch, means the unpatched tail is the incident class. The bug is not new. The catalog row is.

Who / what is affected

AssetWhat to assumeStatus
GS1900 models in Zyxel’s June table, firmware 2.90(*.1)C0 and earlierIn scope for CVE-2026-7273CONFIRMED vendor
Same models on 2.90(*.2)C0Patch claimed by vendor; still hunt if management was reachableCONFIRMED patch; compromise UNKNOWN unless you look
GS1900 management CGI reachable from untrusted networksHighest-leverage exposure; matches GreyNoise collectionASSESSED from vendor vector + GreyNoise geography
Other Zyxel switch familiesNot this CVECONFIRMED vendor “not listed = unaffected” for on-market
Factory-default adminIndependent finding; 564/996 in GreyNoise setCONFIRMED GreyNoise for that set only
Named victim orgsNot publishedUNKNOWN
OT / ICS / water / processNot claimedNo evidence
CISA ransomware fieldUnknownCONFIRMED catalog

Technical context

RWP is not reproducing HTTP bodies, offset tables, or the GOT-versus-stack modes in the actor’s script.

What the primary records actually give defenders:

ATT&CK mapping for what is stated:

Follow-on that is not claimed: ransomware-Known, a named APT in the KEV row, VLAN/PoE sabotage, or traffic interception as observed tradecraft.

Threat / exploitation status

ClaimStatusBasis
In KEV, added 21 Sep, due 24 Sep, catalog 2026.09.21 count 1717CONFIRMEDCISA alert + JSON
Exploitation in the wildCONFIRMED as KEV criterionCISA
996 switches / 48 countries / ~17 Aug startCONFIRMED as GreyNoise telemetryGreyNoise 21 Sep
First public in-wild write-upCONFIRMED as GreyNoise’s claim as of 17 SepGreyNoise; CISA does not name them
Vendor advisory updated for exploitationNo as of this morningBC, THN
Ransomware useUnknownCatalog field
Forensic triage requiredYesCatalog field
Actor identityASSESSED Chinese-speaking MCA, possibly Red Heron-relatedGreyNoise; not independently re-derived
LLM-written toolingASSESSED by GreyNoise from code-comment patternsNot proven
OT / physical-process impactNot claimedNo evidence

High confidence on: CVE ID, KEV dates, due date, catalog version and count, CVSS 8.8 adjacent vector, June patch table, forensic-triage flag, ransomware Unknown, Zyxel’s 13 KEV CVEs, GreyNoise’s 996 / 564 / country table as their measurements. Moderate confidence that internet-reachable management is the dominant real-world condition (geography of 996; no full internet census). Low confidence on CISA’s unpublished exploitation evidence, on Red Heron as a firm identity for the switch work, and on any victim beyond GreyNoise’s unlabeled set.

What defenders should do

  1. Inventory GS1900, not “Zyxel.” Model, firmware string, management IP, and whether HTTP/HTTPS to the CGI is reachable from anywhere that is not the dedicated out-of-band network. Include MSP-managed closets, camera VLANs, and lab switches. Record internet exposure for BOD 26-04.
  1. **Patch to the 2.90(*.2)C0 build for that SKU, then reboot onto it.** Confirm the running firmware, not the file you downloaded. If the box is out of Zyxel’s vulnerability-support window and has no row in the June table, replace it; do not invent a backport.
  1. Treat reachable management as a compromise-until-proven-otherwise problem. CISA’s required action includes forensics-triage language. Before you call the ticket closed: export running config, check for unexpected users, compare firmware and boot image, look for unexpected files under the web temp path GreyNoise named, and pull authentication logs if the box still has them. Factory-default admin is a finding even on a patched switch.
  1. Move the CGI off untrusted networks. Management VRF or OOB. No WAN NAT to 80/443 on the switch. No shared VLAN with cameras and guests. Adjacent scoring assumes you already did this. GreyNoise’s count says many people did not.
  1. Hunt the campaign only as campaign, not as this CVE. GreyNoise’s broader IOC table (backdoor hashes, *.981666.xyz, staging 74.48.66[.]73, accounts kapibala / kapibala2) is for the operator’s other jobs. Do not declare a GS1900 clean because those hashes are absent. Do not declare a WordPress host related because a GS1900 was collected.
  1. Sequence the rest of the federal list. The [Linux kernel trio](/posts/2026-09-19-linux-kernel-kev-ktls-ebtables-afalg/) was due yesterday. [Cisco ISE CVE-2026-76460](/posts/2026-09-17-cisco-ise-cve-2026-76460-auth-bypass/) and [SEG CVE-2026-76461](/posts/2026-09-15-cisco-seg-cve-2026-76461-sqli/) are already this month’s identity-plane tops. [vCenter CVE-2026-59310](/posts/2026-09-16-vmware-vcenter-cve-2026-59310-ransomware/) remains ransomware-Known. CVE-2026-7273 is the new three-day clock.

This is not an exploitation guide. Use the vendor firmware table and the management-plane inventory.

RWP assessment

Score 8.5. CISA put a June CGI RCE on a Thursday clock. GreyNoise had already counted 996 collected switches, more than half still on factory defaults, with the United States second in their table. That is a better-evidenced network-device KEV than most 9.8s that ship with no victim geography.

It outranks Arctic Wolf’s CVE-2026-32996 Veeam Agent local SYSTEM (public PoC 14 September; local; not KEV). It outranks WordPress CVE-2026-93485 Comment2Shell (7.1.1 on 17 September; admin session required; THN: no in-wild, not KEV). It outranks Bishop Fox’s Veeam Service Provider Console chain (CVE-2026-58073 / CVE-2026-58072, research on an August 9.3.0 patch, no confirmed exploitation this window). It outranks the Colorado water-utility OT reports (late-August events, unnamed private systems serving fewer than 200 people, foreign actors unconfirmed, no water-quality impact) as a daily — that is a process-manipulation story for the weekly OT book, not a KEV with a 24 September due date. [Jade Sleet](/posts/2026-09-21-jade-sleet-it-services-flatroof-roofdeck/) is yesterday.

The failure mode to sand down is “adjacent, so we are fine” and its twin, “we patched in June.” If the CGI still answers on an address you do not control, you are in GreyNoise’s denominator. If admin is still the factory account, you were in it twice.

What we are watching

Sources

Sources

  1. CISA — Adds one KEV CVE-2026-7273
  2. CISA — KEV JSON feed catalog 2026.09.21
  3. CISA — Known Exploited Vulnerabilities Catalog
  4. CISA — BOD 26-04
  5. Zyxel — GS1900 stack-based buffer overflow advisory CVE-2026-7273
  6. NVD — CVE-2026-7273
  7. CVE — CVE-2026-7273
  8. GreyNoise — Open Season on Kapibala
  9. BleepingComputer — CISA orders feds to patch Zyxel GS1900 by Thursday
  10. The Hacker News — Zyxel and Veeam flaws under active exploitation
  11. INCIBE — GS1900 buffer overflow advisory