CVE Tools
Back to feed
Exploited in the wild GS1900-series switches Red Heron data-breach ZyXEL rce

Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers

SecurityWeek·By Ionut Arghire··1 min read
CVE Tools coverage

Chinese threat actor Red Heron has exploited CVE-2026-7273, a CVSS 8.8 unauthenticated stack-based buffer overflow in ZyXEL GS1900-series switches. GreyNoise observed attacks in 48 countries that used crafted HTTP requests to run commands and steal hashed root credentials, device configurations, and network data from 996 systems. ZyXEL released updates for ten affected models in June, and CISA has added the flaw to its Known Exploited Vulnerabilities catalog after the campaign exposed many devices still using factory-default credentials.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store