A recent cybersecurity incident has highlighted vulnerabilities in ZyXEL GS1900 switches, exploited by a Chinese hacking group for extracting sensitive data globally. This critical security issue, identified as CVE-2026-7273, poses a significant threat, according to the threat intelligence firm GreyNoise.
Details of the Vulnerability
The flaw, marked with a CVSS score of 8.8, is a stack-based buffer overflow vulnerability that attackers can exploit without requiring authentication. By sending specially crafted HTTP requests, hackers can execute OS commands on affected devices. ZyXEL addressed this issue by releasing security updates for ten models of the GS1900 switches in June.
Despite these patches, GreyNoise reported that a Chinese hacking collective exploited the vulnerability in August, targeting ZyXEL devices across 48 countries. The malicious actors used an obfuscated Python script to steal crucial information such as hashed root credentials and network configurations from nearly 1,000 compromised devices.
Targeted Firmware and Exploitation Details
The attackers directed their efforts specifically at firmware versions 2.10-2.90 of the GS1900-24 model, although their script allowed for adaptability to other versions affected by the vulnerability. Alarmingly, 564 devices still utilized factory default credentials, making them easy targets for future breaches.
In response to this threat, the US Cybersecurity and Infrastructure Security Agency (CISA) included CVE-2026-7273 in its Known Exploited Vulnerabilities (KEV) catalog. Federal agencies have been urged to apply patches within a three-day window, in compliance with directive BOD 26-04.
Broader Implications and Additional Attacks
The same hacking group was previously observed leveraging a series of Ubiquiti vulnerabilities to achieve remote code execution, as well as exploiting WordPress installations in attacks conducted in July. These attacks primarily targeted small businesses and government entities, with one significant breach involving over 18,000 sensitive records from a western governmental organization.
GreyNoise suggests that the responsible hackers may be associated with the Red Heron group, known for exploiting vulnerabilities in Gitea and targeting numerous systems globally. The unfolding situation underscores the critical need for organizations to update their systems and remain vigilant against cybersecurity threats.
As the cybersecurity landscape evolves, staying informed and proactive in patching vulnerabilities is crucial for safeguarding sensitive information and maintaining network integrity.
