CVE-2026-7273
Una vulnerabilità di buffer overflow basato sullo stack nel programma CGI del firmware Zyxel GS1900-48HPv2 fino alla versione 2.90(ABTQ.1)C0 potrebbe consentire a un attaccante non autenticato basato sulla LAN di sfruttare la falla ed eventualmente eseguire comandi del sistema operativo tramite una richiesta HTTP appositamente predisposta.
Sfruttata attivamente
- Nel catalogo CISA delle vulnerabilità sfruttate dal 21 set 2026
- Le agenzie federali statunitensi devono correggerla entro il 24 set 2026 (direttiva BOD 22-01)
- Primo attacco osservato 97 giorni dopo la divulgazione
- Confermata dai sensori, non solo da segnalazioni
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Fonte: CISA KEV · 21 set 2026 21 set 2026
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HProdotti coinvolti
| Vendor | Prodotto | Versioni |
|---|---|---|
| zyxel | gs1900-8 firmware | < 2.90\(aahh.2\)c0 |
| zyxel | gs1900-8 | - |
| zyxel | gs1900-8hp firmware | < 2.90\(aahi.2\)c0 |
| zyxel | gs1900-8hp | - |
| zyxel | gs1900-10hp firmware | < 2.90\(aazi.2\)c0 |
| zyxel | gs1900-10hp | - |
| zyxel | gs1900-16 firmware | < 2.90\(aahj.2\)c0 |
| zyxel | gs1900-16 | - |
| zyxel | gs1900-24 firmware | < 2.90\(aahl.2\)c0 |
| zyxel | gs1900-24 | - |
| zyxel | gs1900-24e firmware | < 2.90\(aahk.2\)c0 |
| zyxel | gs1900-24e | - |
| zyxel | gs1900-24ep firmware | < 2.90\(abto.2\)c0 |
| zyxel | gs1900-24ep | - |
| zyxel | gs1900-24hpv2 firmware | < 2.90\(abtp.2\)c0 |
| zyxel | gs1900-24hpv2 | - |
| zyxel | gs1900-48 firmware | < 2.90\(aahn.2\)c0 |
| zyxel | gs1900-48 | - |
| zyxel | gs1900-48hpv2 firmware | < 2.90\(abtq.2\)c0 |
| zyxel | gs1900-48hpv2 | - |
Articoli correlati
VulnerabilitàAttacchi in corso mettono a rischio gli switch Zyxel e gli endpoint Windows protetti da Veeam
Attacchi attivi sfruttano switch Zyxel GS1900 e Veeam Agent Windows: esecuzione comandi e escalation a SYSTEM. Aggiorna subito il firmware.
VulnerabilitàLa falla nei switch Zyxel sfruttata attivamente fa scattare una finestra federale di tre giorni per l’applicazione delle patch
CISA conferma lo sfruttamento attivo della falla CVE-2026-7273 negli switch Zyxel GS1900: patch obbligatoria entro il 24 settembre 2026.
This product uses the NVD API but is not endorsed or certified by the NVD.
La descrizione tecnica è una nostra traduzione del testo originale NVD, in inglese.