INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Zyxel Switch Vulnerability Exploited by Chinese Hackers for Data Theft
| 2026-09-22 11:55 CRITICAL HIGH EXPLOITED VULNERABILITY STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A Chinese threat actor has been targeting vulnerable ZyXEL GS1900 switches worldwide for sensitive information exfiltration, with 996 devices compromised in August. The attack uses a heavily obfuscated Python script to extract hashed root credentials, configuration details, and networking information from affected devices. Meanwhile, the same threat actor was also seen using a chain of Ubiquiti vulnerabilities leading to remote code execution (RCE) and targeting WordPress installations in July, with over 18,000 sensitive records stolen from one western governmental organization's backend database. The attack exploits a stack-based buffer overflow vulnerability tracked as CVE-2026-7273, which was patched by ZyXEL in June but remains unpatched on many devices worldwide.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2024-40891, CVE-2026-7273 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2024-40891CVE-2024-40891
CVE-2026-7273CVE-2026-7273
Target & Sectors
Global Scope
governmentgovernment
Incident Timeline
June 16
Threat actors exploited a previously known vulnerability in Zyxel's products, prompting the company to release security updates on June 16.
17 September 2026
Threat actors used the newly added Zyxel vulnerability to target systems, with this being the first publicly documented case of exploitation in the wild.
September 22, 2026
U.S. CISA added the Zyxel vulnerability to its Known Exploited Vulnerabilities catalog on September 22, 2026.
Click on any entity below to view its context and source!
tactic
T1588.006 - Vulnerabilities
U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 22, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog.
attribution
Known Exploited
U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 22, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog.
attribution
Zyxel
U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog
Pierluigi Paganini
September 22, 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog.
2026/09/22
A Chinese threat actor has been targeting vulnerable ZyXEL GS1900 switches worldwide for sensitive information exfiltration, tracked as CVE-2026-7273.
Click on any entity below to view its context and source!
organisation
Known Exploited
On Monday, the US cybersecurity agency
CISA added
CVE-2026-7273 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days, as mandated by BOD 26-04.
organisation
KEV
On Monday, the US cybersecurity agency
CISA added
CVE-2026-7273 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days, as mandated by BOD 26-04.
organisation
CGI
The flaw (tracked as
CVE-2026-7273
) stems from a stack-based buffer overflow in the CGI program that lets threat actors without privileges on the local area network (LAN) execute OS commands via maliciously crafted HTTP requests.
“A stack-based buffer overflow vulnerability in the CGI program of the Zyxel GS1900 series switch firmware could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.”
reads the advisory
.
organisation
LAN
The flaw (tracked as
CVE-2026-7273
) stems from a stack-based buffer overflow in the CGI program that lets threat actors without privileges on the local area network (LAN) execute OS commands via maliciously crafted HTTP requests.
“A stack-based buffer overflow vulnerability in the CGI program of the Zyxel GS1900 series switch firmware could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.”
reads the advisory
.
organisation
ZyXEL GS1900 Smart Managed Switches
"GreyNoise discovered the MCA targeted ZyXEL GS1900 Smart Managed Switches globally with a novel exploit of CVE-2026-7273.
infrastructure
Linux
Related:
WordPress Patches ‘Click2Shell’ Vulnerability
Related:
Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
Related:
organisation
WordPress
The same threat actor was also seen using a chain of Ubiquiti vulnerabilities leading to remote code execution (RCE), and targeting WordPress installations in July, in attacks against small business and government entities.
organisation
GreyNoise
A Chinese threat actor has been targeting vulnerable ZyXEL GS1900 switches worldwide for sensitive information exfiltration, threat intelligence firm GreyNoise warns.
According to GreyNoise, a suspected Chinese-speaking malicious cyber actor (MCA) has compromised nearly 1,000 Zyxel GS1900 switches as part of a campaign that targeted over a dozen other vulnerabilities affecting a wide range of software and tech products.
organisation
Recent ZyXEL Switch Vulnerability Exploited
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers.
organisation
ZyXEL
On Monday, GreyNoise
warned
that it was exploited by a Chinese hacking group in August against ZyXEL devices in 48 countries.
According to GreyNoise, a suspected Chinese-speaking malicious cyber actor (MCA) has compromised nearly 1,000 Zyxel GS1900 switches as part of a campaign that targeted over a dozen other vulnerabilities affecting a wide range of software and tech products.
“A stack-based buffer overflow vulnerability in the CGI program of the Zyxel GS1900 series switch firmware could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.”
reads the advisory
.
organisation
MCA
According to GreyNoise, a suspected Chinese-speaking malicious cyber actor (MCA) has compromised nearly 1,000 Zyxel GS1900 switches as part of a campaign that targeted over a dozen other vulnerabilities affecting a wide range of software and tech products.
infrastructure
2.10-2
“While the script explicitly targets firmware versions 2.10-2.90 of the GS1900-24, it does provide command-line options (e.g., libc base address, global offsets) for targeting other firmware in scope for the vulnerability,” GreyNoise says.
infrastructure
996 vulnerable devices
The threat actor used a heavily obfuscated Python script to exfiltrate sensitive information such as hashed root credentials, configuration details, and networking information from 996 vulnerable devices.
organisation
Acronis
The cybersecurity firm believes that the threat actor is the same as or closely related to the
Red Heron
hacking group that Acronis observed exploiting a Gitea vulnerability in attacks targeting hundreds of systems worldwide.
data_breach
564 credentials
While the hackers extracted hashed credentials, 564 of the compromised devices had factory default credentials, leaving the door open to future attacks.
data_breach
18,000 sensitive records
“The most egregious data theft occurred against an identified western governmental organization involving more than 18,000 sensitive records stolen from its backend database,” GreyNoise says.
infrastructure
2.90
The vulnerability has been fixed in the following firmware versions:
Affected model
Affected version
Patch availability
GS1900-8
2.90(AAHH.1)C0 and earlier
2.90(AAHH.2)C0
GS1900-8HP
2.90(AAHI.1)C0 and earlier
2.90(AAHI.2)C0
GS1900-10HP
2.90(AAZI.1)C0 and earlier
2.90(AAZI.2)C0
GS1900-16
2.90(AAHJ.1)C0 and earlier
2.90(AAHJ.2)C0
GS1900-24
2.90(AAHL.1)C0 and earlier
2.90(AAHL.2)C0
GS1900-24E
2.9…
"
Affected model
Affected version
Patch availability
GS1900-8
2.90(AAHH.1)C0 and earlier
2.90(AAHH.2)C0
GS1900-8HP
2.90(AAHI.1)C0 and earlier
2.90(AAHI.2)C0
GS1900-10HP
2.90(AAZI.1)C0 and earlier
2.90(AAZI.2)C0
GS1900-16
2.90(AAHJ.1)C0 and earlier
2.90(AAHJ.2)C0
GS1900-24
2.90(AAHL.1)C0 and earlier
2.90(AAHL.2)C0
GS1900-24E
2.90(AAHK.1)C0 and earlier
2.9…
organisation
Zyxel’s
The vulnerability affects the CGI component of Zyxel’s GS1900 switch firmware.
financial
04 BOD
"While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities.
organisation
CVE-2024-40891
In February, the company warned
that it had no plans to patch
a pair of
actively exploited
zero-day bugs (CVE-2024-40891 and CVE-2024-40891) affecting end-of-life routers still available for sale online.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
September 24, 2026
CISA orders federal agencies to fix the Zyxel vulnerability by September 24, 2026.
Tactical Metrics
Metrics
infrastructure
2.10-2
Software Version
Click for context!
“While the script explicitly targets firmware versions 2.10-2.90 of the GS1900-24, it does provide command-line options (e.g., libc base address, global offsets) for targeting other firmware in scope for the vulnerability,” GreyNoise says.
Metrics
infrastructure
Linux
Affected Product
Related:
WordPress Patches ‘Click2Shell’ Vulnerability
Related:
Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
Related:
Metrics
infrastructure
996
Vulnerable Devices
The threat actor used a heavily obfuscated Python script to exfiltrate sensitive information such as hashed root credentials, configuration details, and networking information from 996 vulnerable devices.
Metrics
data_breach
564
Credentials
While the hackers extracted hashed credentials, 564 of the compromised devices had factory default credentials, leaving the door open to future attacks.
Metrics
data_breach
18,000
Sensitive Records
“The most egregious data theft occurred against an identified western governmental organization involving more than 18,000 sensitive records stolen from its backend database,” GreyNoise says.
Metrics
infrastructure
2.90
Software Version
The vulnerability has been fixed in the following firmware versions:
Affected model
Affected version
Patch availability
GS1900-8
2.90(AAHH.1)C0 and earlier
2.90(AAHH.2)C0
GS1900-8HP
2.90(AAHI.1)C0 and earlier
2.90(AAHI.2)C0
GS1900-10HP
2.90(AAZI.1)C0 and earlier
2.90(AAZI.2)C0
GS1900-16
2.90(AAHJ.1)C0 and earlier
2.90(AAHJ.2)C0
GS1900-24
2.90(AAHL.1)C0 and earlier
2.90(AAHL.2)C0
GS1900-24E
2.9…
"
Affected model
Affected version
Patch availability
GS1900-8
2.90(AAHH.1)C0 and earlier
2.90(AAHH.2)C0
GS1900-8HP
2.90(AAHI.1)C0 and earlier
2.90(AAHI.2)C0
GS1900-10HP
2.90(AAZI.1)C0 and earlier
2.90(AAZI.2)C0
GS1900-16
2.90(AAHJ.1)C0 and earlier
2.90(AAHJ.2)C0
GS1900-24
2.90(AAHL.1)C0 and earlier
2.90(AAHL.2)C0
GS1900-24E
2.90(AAHK.1)C0 and earlier
2.9…
Metrics
financial
4
Bod
"While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities.
Intelligence Sources
Security Affairs
2026-09-22
SecurityWeek
2026-09-22
BleepingComputer
2026-09-22
CISA orders feds to patch Zyxel flaw exploited for data theft
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T11:27
Comprehensive Tactical Telemetry
Highly Correlated Entities
15x
organisation
Identified Entity
Known Exploited
entity
13x
attribution
Attributing Entity
CISA Retires Weekly
authority
7x
timeline
Temporal Reference
26-04
date
4x
tactic
Cyber Operation Type
Remote Code Execution
tactic
2x
source region
Origin Country
United States
country
2x
vulnerability
Exploited CVE
CVE-2026-7273
cve
2x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
2x
infrastructure
Software Version
2.10-2
version
Contextual Telemetry
Context Block
20 METRICS
general metric
Cve-2026
7,273
cve-2026
industry
Targeted Sector
Government
sector
vulnerability
CVSS Score
9
score
general metric
Versions
2
versions
infrastructure
Affected Product
Linux
software
general metric
Kernel Vulnerabilities
3
kernel vulnerabilities
general metric
Countries
48
countries
infrastructure
Vulnerable Devices
996
vulnerable devices
data breach
Credentials
564
credentials
data breach
Sensitive Records
18,000
sensitive records
general metric
2.90(Aahh.1)C0
8
2.90(aahh.1)c0
general metric
Earlier 2.90(Aazi.2)C0 Gs1900 2.90(Aahj.1)C0
16
earlier 2.90(aazi.2)c0 gs1900 2.90(aahj.1)c0
general metric
Earlier 2.90(Aahj.2)C0 Gs1900 2.90(Aahl.1)C0
24
earlier 2.90(aahj.2)c0 gs1900 2.90(aahl.1)c0
general metric
Binding Operational Directive
26
binding operational directive
financial
Bod
4
bod
general metric
Gs1900 Switches
1,000
gs1900 switches
general metric
Zyxel Vulnerabilities
13
zyxel vulnerabilities
general metric
Zyxel Switches
996
zyxel switches
general metric
Businesses
1,000,000
businesses
general metric
Markets
150
markets
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.