轉發 國家資安資訊分享與分析中心 資安訊息警訊 NISAC-200-202610-00000003
[內容說明]
研究人員發現Zyxel GS1900系列交換器存在堆疊型緩衝區溢位(Stack-based Buffer Overflow)漏洞(CVE-2026-7273),未經身分鑑別之同一區網攻擊者可藉由向CGI程式傳送特製HTTP請求,觸發記憶體毀損,進而於受影響裝置執行作業系統指令。該漏洞已遭駭客濫用,請儘速確認並進行修補。
[影響平台]
Zyxel GS1900-10HP 2.90(AAZI.1)C0(含)以前版本
Zyxel GS1900-16 2.90(AAHJ.1)C0(含)以前版本
Zyxel GS1900-24 2.90(AAHL.1)C0(含)以前版本
Zyxel GS1900-24E 2.90(AAHK.1)C0(含)以前版本
Zyxel GS1900-24EP 2.90(ABTO.1)C0(含)以前版本
Zyxel GS1900-24HPv2 2.90(ABTP.1)C0(含)以前版本
Zyxel GS1900-48 2.90(AAHN.1)C0(含)以前版本
Zyxel GS1900-48HPv2 2.90(ABTQ.1)C0(含)以前版本
Zyxel GS1900-8 2.90(AAHH.1)C0(含)以前版本
Zyxel GS1900-8HP 2.90(AAHI.1)C0(含)以前版本
[建議措施]
官方已針對漏洞釋出修補或更新,請參考官方說明進行處置,網址如下: https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026
[參考資料]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-7273
2. https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026
Forwarded from National Information Security Analysis Center Security Information Alert NISAC-200-202610-00000003
[Content Description]
Researchers have discovered a Stack-based Buffer Overflow vulnerability (CVE-2026-7273) in Zyxel GS1900 series switches. An unauthenticated attacker on the same local network can trigger memory corruption by sending specially crafted HTTP requests to the CGI program, thereby executing OS commands on affected devices. The vulnerability has been exploited by hackers. Please confirm and apply patches as soon as possible.
[Affected Platforms]
Zyxel GS1900-10HP versions 2.90(AAZI.1)C0 (inclusive) and earlier
Zyxel GS1900-16 versions 2.90(AAHJ.1)C0 (inclusive) and earlier
Zyxel GS1900-24 versions 2.90(AAHL.1)C0 (inclusive) and earlier
Zyxel GS1900-24E versions 2.90(AAHK.1)C0 (inclusive) and earlier
Zyxel GS1900-24EP versions 2.90(ABTO.1)C0 (inclusive) and earlier
Zyxel GS1900-24HPv2 versions 2.90(ABTP.1)C0 (inclusive) and earlier
Zyxel GS1900-48 versions 2.90(AAHN.1)C0 (inclusive) and earlier
Zyxel GS1900-48HPv2 versions 2.90(ABTQ.1)C0 (inclusive) and earlier
Zyxel GS1900-8 versions 2.90(AAHH.1)C0 (inclusive) and earlier
Zyxel GS1900-8HP versions 2.90(AAHI.1)C0 (inclusive) and earlier
[Recommended Measures]
The vendor has released patches or updates for the vulnerability. Please refer to the official instructions for handling. The URL is as follows: https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026
[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-7273
2. https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026
【資安漏洞預警】Zyxel GS1900系列交換器存在高風險安全漏洞(CVE-2026-7273),請儘速確認並進行修補
【Security Vulnerability Alert】Zyxel GS1900 series switches contain a high-risk security vulnerability (CVE-2026-7273). Please confirm and apply patches as soon as possible
公告類別:行政公告
發佈日期:2026/10/05 至 2027/04/05
點閱數:42
返回列表



