Zyxel has issued a security update advisory for the GS1900 Series switches.
The resolved vulnerability is CVE-2026-7273, a stack-based buffer overflow vulnerability occurring in the CGI program (a program that processes web requests).
Affected products are those running the following versions or earlier:
GS1900-8: 2.90(AAHH.1)C0 or earlier.
GS1900-8HP: 2.90(AAHI.1)C0 or earlier.
GS1900-10HP: 2.90(AAZI.1)C0 or earlier.
GS1900-16: 2.90(AAHJ.1)C0 or earlier.
GS1900-24: 2.90 (AAHL.1) C0 or less.
GS1900-24E: 2.90 (AAHK.1) C0 or less.
GS1900-24EP: 2.90 (ABTO.1) C0 or less.
GS1900-24HPv2: 2.90 (ABTP.1) C0 or less.
GS1900-48: 2.90 (AAHN.1) C0 or lower.
GS1900-48HPv2: 2.90 (ABTQ.1) C0 or lower.
Zyxel has provided Vulnerability Patches through the latest update and advises users to update to the latest version with Vulnerability Patches as instructed on the reference site.
The versions with Vulnerability Patches are as follows: