Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
A stack-based buffer overflow vulnerability (CVE-2026-7273) in ZyXEL GS1900 switches has been exploited by a Chinese threat actor to exfiltrate sensitive information from nearly 1,000 devices worldwide. The vulnerability allows unauthenticated OS command execution via crafted HTTP requests. ZyXEL released patches for ten GS1900 models in June 2026. The attacker used an obfuscated Python script targeting firmware versions 2.10 to 2.90, extracting hashed root credentials and configuration data. Over half of the compromised devices used factory default credentials, increasing risk. The US CISA added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating patching within three days for federal agencies. The same threat actor also exploited other vulnerabilities in Ubiquiti devices and WordPress installations. The threat actor is suspected to be linked to the Red Heron group.
AI Analysis
Technical Summary
CVE-2026-7273 is a stack-based buffer overflow vulnerability in ZyXEL GS1900 switches that permits unauthenticated remote OS command execution via crafted HTTP requests. ZyXEL issued security updates in June 2026 for ten GS1900 switch models to address this flaw. In August 2026, a Chinese hacking group exploited this vulnerability globally, targeting firmware versions 2.10 through 2.90 with a heavily obfuscated Python script to exfiltrate sensitive information including hashed root credentials and network configurations from 996 devices. Many compromised devices retained factory default credentials, facilitating further exploitation. The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-7273 to its Known Exploited Vulnerabilities catalog and mandated rapid patching for federal agencies. The threat actor has also exploited other vulnerabilities in Ubiquiti devices and WordPress platforms and is potentially linked to the Red Heron hacking group.
Potential Impact
The vulnerability enables unauthenticated remote attackers to execute OS commands on affected ZyXEL GS1900 switches, leading to exfiltration of sensitive information such as hashed root credentials, device configurations, and network details. Nearly 1,000 devices were compromised worldwide across 48 countries. The presence of factory default credentials on many devices increases the risk of further compromise. The exploitation has resulted in significant data theft, including over 18,000 sensitive records from a western governmental organization. The vulnerability's inclusion in CISA's KEV catalog underscores its criticality and active exploitation.
Mitigation Recommendations
ZyXEL released official security updates in June 2026 that patch the vulnerability in ten GS1900 switch models. Organizations should apply these patches immediately. The US CISA mandates federal agencies to patch within three days. Devices should also be audited to replace factory default credentials with strong, unique passwords to reduce risk of further compromise. No additional mitigation is indicated beyond patching and credential management.
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
Description
A stack-based buffer overflow vulnerability (CVE-2026-7273) in ZyXEL GS1900 switches has been exploited by a Chinese threat actor to exfiltrate sensitive information from nearly 1,000 devices worldwide. The vulnerability allows unauthenticated OS command execution via crafted HTTP requests. ZyXEL released patches for ten GS1900 models in June 2026. The attacker used an obfuscated Python script targeting firmware versions 2.10 to 2.90, extracting hashed root credentials and configuration data. Over half of the compromised devices used factory default credentials, increasing risk. The US CISA added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating patching within three days for federal agencies. The same threat actor also exploited other vulnerabilities in Ubiquiti devices and WordPress installations. The threat actor is suspected to be linked to the Red Heron group.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-7273 is a stack-based buffer overflow vulnerability in ZyXEL GS1900 switches that permits unauthenticated remote OS command execution via crafted HTTP requests. ZyXEL issued security updates in June 2026 for ten GS1900 switch models to address this flaw. In August 2026, a Chinese hacking group exploited this vulnerability globally, targeting firmware versions 2.10 through 2.90 with a heavily obfuscated Python script to exfiltrate sensitive information including hashed root credentials and network configurations from 996 devices. Many compromised devices retained factory default credentials, facilitating further exploitation. The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-7273 to its Known Exploited Vulnerabilities catalog and mandated rapid patching for federal agencies. The threat actor has also exploited other vulnerabilities in Ubiquiti devices and WordPress platforms and is potentially linked to the Red Heron hacking group.
Potential Impact
The vulnerability enables unauthenticated remote attackers to execute OS commands on affected ZyXEL GS1900 switches, leading to exfiltration of sensitive information such as hashed root credentials, device configurations, and network details. Nearly 1,000 devices were compromised worldwide across 48 countries. The presence of factory default credentials on many devices increases the risk of further compromise. The exploitation has resulted in significant data theft, including over 18,000 sensitive records from a western governmental organization. The vulnerability's inclusion in CISA's KEV catalog underscores its criticality and active exploitation.
Mitigation Recommendations
ZyXEL released official security updates in June 2026 that patch the vulnerability in ten GS1900 switch models. Organizations should apply these patches immediately. The US CISA mandates federal agencies to patch within three days. Devices should also be audited to replace factory default credentials with strong, unique passwords to reduce risk of further compromise. No additional mitigation is indicated beyond patching and credential management.
Technical Details
- Classification
- {"confidence":0.79,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/recent-zyxel-switch-vulnerability-exploited-by-chinese-hackers/","fetched":true,"fetchedAt":"2026-09-22T12:02:46.298Z","wordCount":969}
Threat ID: 6ab26e66f7a7c5410620ba58
Added to database: 09/22/2026, 12:02:46 UTC
Last enriched: 09/22/2026, 12:02:53 UTC
Last updated: 09/23/2026, 02:49:26 UTC
Views: 23
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.