CVE-2026-7273
Analyzed
Analyzed - Analysis Complete
Stack-Based Buffer Overflow in Zyxel GS1900-48HPv2 Firmware
Vulnerability report for CVE-2026-7273, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-06-16
Last updated on: 2026-09-22
Assigner: Zyxel Corporation
Description
Description
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zyxel | gs1900-8_firmware | to 2.90(aahh.2 (exc) |
| zyxel | gs1900-8hp_firmware | to 2.90(aahi.2 (exc) |
| zyxel | gs1900-10hp_firmware | to 2.90(aazi.2 (exc) |
| zyxel | gs1900-16_firmware | to 2.90(aahj.2 (exc) |
| zyxel | gs1900-24_firmware | to 2.90(aahl.2 (exc) |
| zyxel | gs1900-24e_firmware | to 2.90(aahk.2 (exc) |
| zyxel | gs1900-24ep_firmware | to 2.90(abto.2 (exc) |
| zyxel | gs1900-24hpv2_firmware | to 2.90(abtp.2 (exc) |
| zyxel | gs1900-48_firmware | to 2.90(aahn.2 (exc) |
| zyxel | gs1900-48hpv2_firmware | to 2.90(abtq.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-121 | A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function). |