Answer in brief
CVE-2026-7273 records a High severity vulnerability in CISA ADP Vulnrichment. The current sources mark it as known exploited. The current feed maps Zyxel/GS1900-10HP firmware (generic), Zyxel/GS1900-16 firmware (generic), Zyxel/GS1900-24E firmware (generic), Zyxel/GS1900-24EP firmware (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Zyxel/GS1900-10HP firmware (generic), Zyxel/GS1900-16 firmware (generic), Zyxel/GS1900-24E firmware (generic), Zyxel/GS1900-24EP firmware (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Zyxel/GS1900-10HP firmwaregeneric | <= 2.90(AAZI.1)C0 | Not reported |
| Zyxel/GS1900-16 firmwaregeneric | <= 2.90(AAHJ.1)C0 | Not reported |
| Zyxel/GS1900-24E firmwaregeneric | <= 2.90(AAHK.1)C0 | Not reported |
| Zyxel/GS1900-24EP firmwaregeneric | <= 2.90(ABTO.1)C0 | Not reported |
| Zyxel/GS1900-24 firmwaregeneric | <= 2.90(AAHL.1)C0 | Not reported |
| Zyxel/GS1900-24HPv2 firmwaregeneric | <= 2.90(ABTP.1)C0 | Not reported |
| Zyxel/GS1900-48 firmwaregeneric | <= 2.90(AAHN.1)C0 | Not reported |
| Zyxel/GS1900-48HPv2 firmwaregeneric | <= 2.90(ABTQ.1)C0 | Not reported |
| Zyxel/GS1900-8 firmwaregeneric | <= 2.90(AAHH.1)C0 | Not reported |
| Zyxel/GS1900-8HP firmwaregeneric | <= 2.90(AAHI.1)C0 | Not reported |
Published upstream
Jun 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 21, 2026
Added to CISA KEV
Sep 21, 2026
Evidence: source:kev:kev:kev:recordA stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
Quoted source text, attributed separately from HOL analysis.