Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
At a glance
- Severity
- Medium
- Used in attacks
- No flaws named
- Vendors and products
- Zyxel
- Reported by
- 1 outlet
A Chinese threat actor has been targeting vulnerable ZyXEL GS1900 switches worldwide for sensitive information exfiltration, threat intelligence firm GreyNoise warns.
Tracked as CVE-2026-7273 (CVSS score of 8.8), the security defect is described as a stack-based buffer overflow that could be exploited without authentication to execute OS commands via crafted HTTP requests.
ZyXEL rolled out security updates patching the bug in ten GS1900 switch models in June. On Monday, GreyNoise warned that it was exploited by a Chinese hacking group in August against ZyXEL devices in 48 countries.
The threat actor used a heavily obfuscated Python script to exfiltrate sensitive information such as hashed root credentials, configuration details, and networking information from 996 vulnerable devices.
“While the script explicitly targets firmware versions 2.10-2.90 of the GS1900-24, it does provide command-line options (e.g., libc base address, global offsets) for targeting other firmware in scope for the vulnerability,” GreyNoise says.
While the hackers extracted hashed credentials, 564 of the compromised devices had factory default credentials, leaving the door open to future attacks.
Advertisement. Scroll to continue reading.
On Monday, the US cybersecurity agency CISA added CVE-2026-7273 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days, as mandated by BOD 26-04.
The same threat actor was also seen using a chain of Ubiquiti vulnerabilities leading to remote code execution (RCE), and targeting WordPress installations in July, in attacks against small business and government entities.
“The most egregious data theft occurred against an identified western governmental organization involving more than 18,000 sensitive records stolen from its backend database,” GreyNoise says.
The cybersecurity firm believes that the threat actor is the same as or closely related to the Red Heron hacking group that Acronis observed exploiting a Gitea vulnerability in attacks targeting hundreds of systems worldwide.
Related: WordPress Patches ‘Click2Shell’ Vulnerability
Related: Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
Related: In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
Related: CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot
Originally published by SecurityWeek. © SecurityWeek. Written by Ionut Arghire.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-22 11:55 UTC
Related stories
- Apple patches CoreGraphics zero-day flaw exploited in attacks
BleepingComputer · 2026-09-29
- Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The Hacker News · 2026-09-29
- OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot
The Hacker News · 2026-09-29
- One Packet Can Crash OT Servers in Industrial Sectors
Dark Reading · 2026-09-28