CVE-2026-7273
Received
Received - Intake
Stack-Based Buffer Overflow in Zyxel GS1900-48HPv2 Firmware
Publication date: 2026-06-16
Last updated on: 2026-06-16
Assigner: Zyxel Corporation
Description
Description
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zyxel | gs1900-8 | to 2.90(ABTQ.1)C0 (inc) |
| zyxel | gs1900-8hp | to 2.90(ABTQ.1)C0 (inc) |
| zyxel | gs1900-10hp | to 2.90(ABTQ.1)C0 (inc) |
| zyxel | gs1900-16 | to 2.90(ABTQ.1)C0 (inc) |
| zyxel | gs1900-24 | to 2.90(ABTQ.1)C0 (inc) |
| zyxel | gs1900-24e | to 2.90(ABTQ.1)C0 (inc) |
| zyxel | gs1900-24ep | to 2.90(ABTQ.1)C0 (inc) |
| zyxel | gs1900-24hpv2 | to 2.90(ABTQ.1)C0 (inc) |
| zyxel | gs1900-48 | to 2.90(ABTQ.1)C0 (inc) |
| zyxel | gs1900-48hpv2 | to 2.90(ABTQ.1)C0 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-121 | A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function). |