Exploited in the wild GS1900-series switches Red Heron data-breach ZyXEL rce
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
CVE Tools coverage
Chinese threat actor Red Heron has exploited CVE-2026-7273, a CVSS 8.8 unauthenticated stack-based buffer overflow in ZyXEL GS1900-series switches. GreyNoise observed attacks in 48 countries that used crafted HTTP requests to run commands and steal hashed root credentials, device configurations, and network data from 996 systems. ZyXEL released updates for ten affected models in June, and CISA has added the flaw to its Known Exploited Vulnerabilities catalog after the campaign exposed many devices still using factory-default credentials.