The Maivia Gazette

Verified AI news, every morning

Security

Attacker drained configs and root hashes from 996 Zyxel switches; CISA gives agencies until Thursday

CVE-2026-7273 was patched in June, but GreyNoise says exploitation began around August 17 across 48 countries.

Low-angle view of small network switches in a dim wiring closet, with one port glowing red among green ones.
AI-generated illustration, not event photography. The motion is AI-generated from the still.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.

A Chinese-speaking threat actor has exploited a flaw in unpatched Zyxel GS1900 Smart Managed Switches and exfiltrated sensitive data from 996 devices in 48 countries, GreyNoise reported on Monday. The affected switches sit predominantly in Italy, the United States, Taiwan, South Korea and other EU countries, and the GS1900 line is typically deployed in small offices, schools, hotels and retail shops. CVE-2026-7273 is a stack-based buffer overflow in a CGI program on firmware versions 2.90(XXXX.1)C0 and earlier. It lets an unauthenticated attacker on the local network run operating system commands through a crafted HTTP request. Zyxel privately received the report and shipped fixed firmware on June 16. GreyNoise says the attacks began on or about August 17, and that the actor collected device configurations, networking information and hashed root-level credentials; 564 of the victim devices were still using factory default credentials. The exploit code sat inside a Python script. The U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog on Monday and ordered Federal Civilian Executive Branch agencies to secure their switches by Thursday under Binding Operational Directive 26-04. Zyxel has not yet updated its advisory to confirm active exploitation. CISA urged all organizations, not only federal agencies, to prioritize the fix.

Sources

  1. Help Net SecurityAttacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273) - Help Net SecurityPublished · fetched
  2. BleepingComputerCISA orders feds to patch Zyxel flaw exploited for data theftPublished · fetched
  3. Security AffairsU.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalogPublished · fetched

Also in this edition