Zyxel GS1900 Switches Were Hit 62 Days After the Patch, 996 Confirmed Compromised
Security / news
Zyxel GS1900 Switches Were Hit 62 Days After the Patch, 996 Confirmed Compromised
GreyNoise says an attacker exploited CVE-2026-7273 from August 17 and pulled configs and hashed root credentials; 564 victims used factory defaults.

An unauthenticated attacker who can reach the web interface of a Zyxel GS1900 switch can run operating-system commands with one crafted HTTP request (CVE-2026-7273, stack-based buffer overflow in the CGI program). Zyxel shipped firmware for all ten affected models on June 16. GreyNoise says an attacker was exploiting the flaw by August 17 and had taken data from 996 switches in 48 countries.
Install the 2.90(xxxx.2)C0 firmware for your model from the table below, and take the management page off any network you do not control. Then change the credentials: GreyNoise found that 564 of the victims were running factory defaults.
The advisory and the ten models
Zyxel's security advisory describes the attacker as "LAN-based" and "unauthenticated", and says the result is potential OS command execution. Every model is vulnerable at firmware 2.90 build .1 and earlier and fixed at build .2.
| Model | Vulnerable through | Fixed in |
|---|---|---|
| GS1900-8 | 2.90(AAHH.1)C0 | 2.90(AAHH.2)C0 |
| GS1900-8HP | 2.90(AAHI.1)C0 | 2.90(AAHI.2)C0 |
| GS1900-10HP | 2.90(AAZI.1)C0 | 2.90(AAZI.2)C0 |
| GS1900-16 | 2.90(AAHJ.1)C0 | 2.90(AAHJ.2)C0 |
| GS1900-24 | 2.90(AAHL.1)C0 | 2.90(AAHL.2)C0 |
| GS1900-24E | 2.90(AAHK.1)C0 | 2.90(AAHK.2)C0 |
| GS1900-24EP | 2.90(ABTO.1)C0 | 2.90(ABTO.2)C0 |
| GS1900-24HPv2 | 2.90(ABTP.1)C0 | 2.90(ABTP.2)C0 |
| GS1900-48 | 2.90(AAHN.1)C0 | 2.90(AAHN.2)C0 |
| GS1900-48HPv2 | 2.90(ABTQ.1)C0 | 2.90(ABTQ.2)C0 |

What GreyNoise found
According to Help Net Security, which summarises the GreyNoise report, the exploit was a Python script "heavily obfuscated by the commercial obfuscation tool PyArmor" and it went after GS1900-24 firmware from 2.10 through 2.90. The attacker took configuration data, networking information and hashed root-level credentials. GreyNoise describes the operator as a suspected Chinese-speaking actor, possibly connected to earlier WordPress and Gitea campaigns, and is withholding the attacker's IP address "due to victim sensitivities and operational risk."
The countries with the most victims were Italy, the United States, Taiwan and South Korea. BleepingComputer dates the GreyNoise findings to September 17.
Two months from patch to attack
- Exploitation begins (Aug. 17)62 days
- GreyNoise report (Sept. 17)93 days
- CISA catalog entry (Sept. 21)97 days
Source: Zyxel advisory (June 16), Help Net Security and BleepingComputer on GreyNoise (August 17, September 17), CISA (September 21); day counts computed by The Terminal
The 62-day gap is the number to hold onto. A patch existed for the entire period. BleepingComputer adds that Zyxel devices are commonly deployed as default equipment by internet service providers.
The advisory's "LAN-based" wording understates the exposure. Nearly 1,000 compromised switches in 48 countries is not a LAN-only pattern, so at least some management interfaces were reachable from outside. The sources do not say how many, which is an inference and not a measured figure.
CISA's deadline
CISA added CVE-2026-7273 to its Known Exploited Vulnerabilities catalog on September 21 under Binding Operational Directive 26-04, and BleepingComputer reports that CISA now tracks 13 exploited Zyxel vulnerabilities. Help Net Security puts the federal patch deadline at September 24. The CISA alert itself does not print a date.
The entry came one day before the same agency listed Check Point's exploited certificate-validation flaw and F5's BIG-IP bug, and days before Citrix's two NetScaler flaws. All of them are network appliances.
Owners of the ten models should install the .2 build now, then check the switch's saved configuration and root credentials, since those are what left the device.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 03Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 04Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.