Urgent.News

What's breaking now, across thousands of outlets.

Tech

Network segmentation decides whether CVE-2026-7273 in Zyxel GS1900 switches is reachable

Network segmentation decides whether CVE-2026-7273 in Zyxel GS1900 switches is reachable CVE-2026-7273 is a stack-based buffer overflow in the CGI program of the Zyxel GS1900 switch firmware that can lead to OS command execution, and it needs only adjacent network access with no credentials. CISA added it to the Known Exploited Vulnerabilities catalog on 21 September 2026 with a deadline of 24…

CVE-2026-7273 is a critical vulnerability in Zyxel GS1900 switch firmware that allows attackers to execute operating system commands with heightened privileges. This stack-based buffer overflow in the CGI program behind the switch's web management interface can be exploited with adjacent network access, requiring no credentials or user interaction.

The exposure occurs due to network design decisions, such as flat network topologies, sharing VLANs between user devices and switch management, or leaving remote management enabled. The CVSS 3.1 score of 8.8 indicates a high severity risk.

Affected models include various GS1900 series switches, with patches available for those listed. However, even after patching, reducing the attack surface through segmentation becomes crucial. By segregating switch management onto a dedicated VLAN, implementing access control lists (ACLs) to prevent client, guest, and IoT segments from reaching the management address, and disabling remote management on accessible interfaces, organizations can limit the vulnerability's impact.

Verification of the implemented controls should involve attempting to reach the switch's web interface from both client and management segments to ensure the connection is blocked. Recording the firmware version on each device is essential for quick reference in future updates.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Grok 4.7 Just Landed on Amazon Bedrock: First Call, Reasoning Effort, and the Cost Trap

Attributed compile (not original research) Primary source: Grok 4.7 is now available on Amazon Bedrock by Suheel Farooq, Anirban Gupta, Fabio Branco, Ikenna Izugbokwe, and William Yap (AWS Machine…

  • Grok 4.7 model launched on Amazon Bedrock for coding and knowledge work
  • 500K token context window and high reasoning effort level
  • Cost trap due to doubled output tokens per task

More from Tuesday 29 September →