Zyxel fixes buffer overflow in GS1900 switches
Zyxel has released firmware patches for GS1900 series switches affected by a stack-based buffer overflow. The vulnerability, tracked as CVE-2026-7273 with a CVSS v3.1 score of 8.8, sits in the CGI program of the switch firmware and could allow a LAN-based, unauthenticated attacker to execute OS commands via a crafted HTTP request. Zyxel advises installing the available patches. Affected models, vulnerable firmware versions and fixed versions are listed in Zyxel's security advisory.
What this means for your organisation
GS1900 units are inexpensive switches that tend to sit in meeting rooms, warehouses, shops and production halls, often bought locally and never entered into any IT inventory. That is exactly why they go unpatched. The attack requires access to the local network, but the bar is low where the equipment sits in areas customers or suppliers can reach. A compromised switch gives an attacker a stable foothold in a part of the network nobody monitors.
Berigo recommends
- Establish which Zyxel switches you actually have, including units bought outside central IT.
- Install the firmware updates Zyxel specifies for the affected models.
- Place management interfaces for network equipment on a separate network ordinary users cannot reach.
- Bring network equipment into your standard asset register, with a named owner and patching responsibility.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch