Zyxel's GS1900 series managed switches have a vulnerability that is actively being exploited in attacks: an attacker on the same network can take control of the device without a password.
This is CVE-2026-7273, a stack-based buffer overflow in the switches' web interface. A specially crafted HTTP request sent from the local network can execute commands on the device without authentication. CISA has included this vulnerability on its list of those actively exploited in real-world attacks, and the affected series covers most GS1900 models (from GS1900-8 to GS1900-48HPv2), running firmware up to version 2.90(ABTQ.1)C0.
The GS1900 switch is an inexpensive piece of equipment that is widely used in small businesses, typically installed by an IT or internet service provider. Precisely because it’s a device that “just works,” its firmware often goes untouched for years.
The good news is that the vulnerability isn't directly exposed to the internet: the attacker must already be on the local network. The bad news is that this barrier is smaller than it seems—a PC infected via email, a visitor’s laptop, or a device connected to the office Wi-Fi can all serve as a starting point. Whoever gains control of the switch can view and redirect network traffic.
The company does not address the risk on its own; it is managed through the provider. It is important that the firmware of network equipment be kept up to date and that its management not be mixed with the network that visitors access.
What you need to do:
- Ask your IT provider if you are using a Zyxel GS1900 switch and if they have updated its firmware (for the GS1900-48HPv2, the fixed version is 2.90(ABTQ.2)C0).
- Keep the switch’s management interface separate from the guest network; separate the visitor Wi-Fi from the company network.
- Do not allow the switch’s management interface to be accessible from outside the company.
- Request written confirmation from the vendor that the update has been applied.
Network equipment is quiet and often overlooked, but it lies at the very heart of the network. A simple message to your IT provider can clarify in just a few minutes whether you're at risk.
This article was generated with AI assistance.