A Chinese threat actor has exploited a recently disclosed vulnerability in Zyxel GS1900 switches to steal sensitive information, according to threat intelligence firm GreyNoise. Tracked as CVE-2026-7273 and rated 8.8 on the CVSS scale, the flaw is a stack-based buffer overflow that allows unauthenticated attackers to execute operating-system commands through specially crafted HTTP requests. Zyxel released security updates in June for 10 GS1900 models. GreyNoise said the attacks took place in August and affected devices in 48 countries.
The attackers used a heavily obfuscated Python script to extract hashed root credentials, configuration data and networking information from 996 vulnerable devices. Although the script specifically targets firmware versions 2.10–2.90 on the GS1900-24, GreyNoise said command-line options could support attacks against other firmware covered by the vulnerability. Of the compromised devices, 564 still used factory-default credentials, potentially enabling further attacks.
The US Cybersecurity and Infrastructure Security Agency added CVE-2026-7273 to its Known Exploited Vulnerabilities catalogue on Monday, requiring federal agencies to patch it within three days under BOD 26-04. GreyNoise also linked the actor to attacks involving Ubiquiti vulnerabilities and WordPress sites, including one campaign that allegedly stole more than 18,000 sensitive records from a western government organisation.