Back to overview

CVE-2026-7273

HIGH
8.8
CVSS 3.1
Description
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

Metadata

CVE ID
CVE-2026-7273
State
PUBLISHED
Assigner
Zyxel
Reserved
2026-04-28 06:21 UTC
Published
2026-06-16 02:20 UTC
Last updated
2026-06-16 02:20 UTC
Primary CWE
CWE-121
CWE-121 Stack-based buffer overflow
Vendor / Product
Zyxel / GS1900-48HPv2 firmware
Sources
cve.org  ·  NVD

Severity & Metrics

8.8 HIGH CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products (10)
VendorProductPlatformVersions
Zyxel GS1900-10HP firmware <= 2.90(AAZI.1)C0
Zyxel GS1900-16 firmware <= 2.90(AAHJ.1)C0
Zyxel GS1900-24 firmware <= 2.90(AAHL.1)C0
Zyxel GS1900-24E firmware <= 2.90(AAHK.1)C0
Zyxel GS1900-24EP firmware <= 2.90(ABTO.1)C0
Zyxel GS1900-24HPv2 firmware <= 2.90(ABTP.1)C0
Zyxel GS1900-48 firmware <= 2.90(AAHN.1)C0
Zyxel GS1900-48HPv2 firmware <= 2.90(ABTQ.1)C0
Zyxel GS1900-8 firmware <= 2.90(AAHH.1)C0
Zyxel GS1900-8HP firmware <= 2.90(AAHI.1)C0
Weakness (CWE)
CWESourceDescription
CWE-121 cna CWE-121 Stack-based buffer overflow
CVSS scores (1)
ScoreSeverityVersionSourceVector
8.8 HIGH 3.1 cna CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview