Executive Summary

CVE-2026-7273 is a stack-based buffer overflow in the CGI program of Zyxel GS1900 series web-managed switches that allows a LAN-based, unauthenticated attacker to potentially execute operating system commands through a crafted HTTP request. Because these switches frequently sit at the access layer of process control and building automation networks, a successful exploit places an attacker in a position to manipulate the switching fabric that carries live SCADA, PLC, and RTU traffic.

Technical Exposure Breakdown

The flaw resides in the CGI handler that services the switch web management interface. A crafted HTTP request overflows a fixed-size stack buffer, and per the grounding data this condition is reachable without authentication from an adjacent LAN position. That combination is the worst case for a managed switch: no credentials required, no prior foothold, and a network path that already exists in most flat OT segments.

The vulnerable population is broad. Per the grounding data, affected firmware includes GS1900-8 through 2.90(AAHH.2)C0, GS1900-8HP through 2.90(AAHI.2)C0, GS1900-10HP through 2.90(AAZI.2)C0, GS1900-16 through 2.90(AAHJ.2)C0, GS1900-24 through 2.90(AAHL.2)C0, GS1900-24E through 2.90(AAHK.2)C0, GS1900-24EP through 2.90(ABTO.2)C0, GS1900-24HPv2 through 2.90(ABTP.2)C0, GS1900-48 through 2.90(AAHN.2)C0, and GS1900-48HPv2 through 2.90(ABTQ.2)C0. Patch status for these ranges is not confirmed in the grounding data, so operators should treat all listed firmware as exposed until a fixed build is validated in a lab.

The CVSS score is 8.8. The attack vector is adjacent network, which maps directly to how these devices are deployed. GS1900 switches are inexpensive PoE-capable units commonly used to power and connect IP cameras, badge readers, sensors, and small control cabinets. In practice their management planes are rarely isolated from the process VLANs they serve, which shortens the distance between an attacker and the CGI endpoint to a single broadcast domain.

OT Impact and Compliance Risk

Command execution on a switch is not a data confidentiality problem, it is an availability and integrity problem. An attacker with OS-level control can alter VLAN configuration, mirror or drop traffic between a controller and its I/O, disable ports feeding safety-relevant devices, or use the switch as a pivot deeper into the cell. Any of these actions can produce a physical consequence: loss of view, loss of control, or a spurious trip depending on where the device sits.

For NERC CIP environments, a compromised switch inside an electronic security perimeter undermines CIP-005 boundary assumptions and CIP-007 patch and ports-and-services controls. Under IEC 62443, this is a failure at the zone and conduit boundary, specifically the network device that is supposed to enforce segmentation. Water and wastewater operators subject to AWIA 2018 should treat any KEV-listed device in a treatment or distribution network as an item requiring documented risk reassessment. Pipeline operators under TSA SD-02C should confirm this device class is inventoried and that management access is restricted per their segmentation requirements.

Compensating Controls

Do not rely on a vendor patch as the only response. Active scanning of these switches to confirm exposure carries its own risk, and probing the CGI endpoint of an industrial component can hang or brick it. Validate exposure through passive inventory and configuration review rather than intrusive scans.

Because the flaw is unauthenticated and LAN-reachable, network isolation is the control that actually reduces risk. Credential hardening does nothing here.

BreachSpider Intel

BreachSpider tracks CVE-2026-7273 and the full Zyxel GS1900 affected firmware set for KEV status changes and exploitation signals, and provides continuous monitoring for the OT-relevant device classes described above.