Chinese hackers exploit ZyXEL GS1900 switch flaw
Hackers exploited ZyXEL GS1900 buffer overflow CVE-2026-7273 in August, stealing hashed credentials, configuration files and network data from 996 switches in 48 countries.
A Chinese threat actor exploited a stack-based buffer overflow in ZyXEL GS1900 switches in August to extract hashed root credentials, device configuration files and network information from 996 devices across 48 countries. The flaw, tracked as CVE-2026-7273 and rated 8.8 by the CVSS system, allowed unauthenticated execution of operating system commands via specially crafted HTTP requests against vulnerable GS1900 models.
ZyXEL published security updates for ten GS1900 models in June that remedied the vulnerability, but GreyNoise observed that many devices remained on older firmware when the campaign began. GreyNoise identified a heavily obfuscated Python script used in the attacks. The firm noted, “While the script explicitly targets firmware versions 2.10-2.90 of the GS1900-24, it does provide command-line options (e.g., libc base address, global offsets) for targeting other firmware in scope for the vulnerability.”
Of the 996 compromised devices, GreyNoise reported that 564 were still using factory default credentials, which left them exposed to additional access. The exploit sequence used an unauthenticated stack-based overflow to run OS commands on affected switches and then pulled hashed login data, configuration backups and network topology information.
GreyNoise observed the same actor using other exploit chains in the months before and after the GS1900 campaign, including a set of Ubiquiti vulnerabilities that led to remote code execution and attacks against WordPress sites in July. The firm linked the activity to a cluster of intrusions associated with the Red Heron group and noted prior related exploitation of a Gitea flaw in broader attacks. GreyNoise reported, “The most egregious data theft occurred against an identified western governmental organization involving more than 18,000 sensitive records stolen from its backend database.”
U.S. cybersecurity officials added CVE-2026-7273 to the Known Exploited Vulnerabilities catalog and directed federal agencies to apply available patches within three days under Binding Operational Directive 26-04. The inclusion on the KEV list requires agencies to prioritize remediation for the bug.
A stack-based buffer overflow happens when a program writes more data to a memory buffer than it can hold, which can overwrite control data and permit execution of arbitrary code. ZyXEL’s June updates address the flaw. Organizations operating GS1900 switches should verify firmware versions, apply the vendor patches and replace any factory default credentials on devices still in service.







