Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
Reported exploitedGS1900-series switchesRed HeronOur summary
Chinese threat actor Red Heron has exploited CVE-2026-7273, a CVSS 8.8 unauthenticated stack-based buffer overflow in ZyXEL GS1900-series switches. GreyNoise observed attacks in 48 countries that used crafted HTTP requests to run commands and steal hashed root credentials, device configurations, and network data from 996 systems. ZyXEL released updates for ten affected models in June, and CISA has added the flaw to its Known Exploited Vulnerabilities catalog after the campaign exposed many devices still using factory-default credentials.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.