Skip to main content

Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers

0
Critical
Exploit
Published: 09/22/2026 (09/22/2026, 11:55:20 UTC)
Source: SecurityWeek

Description

A stack-based buffer overflow vulnerability (CVE-2026-7273) in ZyXEL GS1900 switches has been exploited by a Chinese threat actor to exfiltrate sensitive information from nearly 1,000 devices worldwide. The vulnerability allows unauthenticated OS command execution via crafted HTTP requests. ZyXEL released patches for ten GS1900 models in June 2026. The attacker used an obfuscated Python script targeting firmware versions 2.10 to 2.90, extracting hashed root credentials and configuration data. Over half of the compromised devices used factory default credentials, increasing risk. The US CISA added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating patching within three days for federal agencies. The same threat actor also exploited other vulnerabilities in Ubiquiti devices and WordPress installations. The threat actor is suspected to be linked to the Red Heron group.

Affected software

Affected versions
>=2.10 <=2.90

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/22/2026, 12:02:53 UTC

Technical Analysis

CVE-2026-7273 is a stack-based buffer overflow vulnerability in ZyXEL GS1900 switches that permits unauthenticated remote OS command execution via crafted HTTP requests. ZyXEL issued security updates in June 2026 for ten GS1900 switch models to address this flaw. In August 2026, a Chinese hacking group exploited this vulnerability globally, targeting firmware versions 2.10 through 2.90 with a heavily obfuscated Python script to exfiltrate sensitive information including hashed root credentials and network configurations from 996 devices. Many compromised devices retained factory default credentials, facilitating further exploitation. The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-7273 to its Known Exploited Vulnerabilities catalog and mandated rapid patching for federal agencies. The threat actor has also exploited other vulnerabilities in Ubiquiti devices and WordPress platforms and is potentially linked to the Red Heron hacking group.

Potential Impact

The vulnerability enables unauthenticated remote attackers to execute OS commands on affected ZyXEL GS1900 switches, leading to exfiltration of sensitive information such as hashed root credentials, device configurations, and network details. Nearly 1,000 devices were compromised worldwide across 48 countries. The presence of factory default credentials on many devices increases the risk of further compromise. The exploitation has resulted in significant data theft, including over 18,000 sensitive records from a western governmental organization. The vulnerability's inclusion in CISA's KEV catalog underscores its criticality and active exploitation.

Mitigation Recommendations

ZyXEL released official security updates in June 2026 that patch the vulnerability in ten GS1900 switch models. Organizations should apply these patches immediately. The US CISA mandates federal agencies to patch within three days. Devices should also be audited to replace factory default credentials with strong, unique passwords to reduce risk of further compromise. No additional mitigation is indicated beyond patching and credential management.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.79,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/recent-zyxel-switch-vulnerability-exploited-by-chinese-hackers/","fetched":true,"fetchedAt":"2026-09-22T12:02:46.298Z","wordCount":969}

Threat ID: 6ab26e66f7a7c5410620ba58

Added to database: 09/22/2026, 12:02:46 UTC

Last enriched: 09/22/2026, 12:02:53 UTC

Last updated: 09/23/2026, 02:49:26 UTC

Views: 23

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses