PT-2026-49603 · Zyxel · Gs1900-48Hpv2
CVE-2026-7273
·
Published
2026-06-16
·
Updated
2026-06-18
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zyxel GS1900-48HPv2 versions prior to 2.90(ABTQ.1)C0
Description
A stack-based buffer overflow exists in the CGI program of the device. A stack-based buffer overflow occurs when a program writes more data to a buffer located on the stack than the buffer is allocated to hold, potentially overwriting adjacent memory. This flaw allows an unauthenticated attacker on the local area network (LAN) to execute operating system commands by sending a specially crafted HTTP request.
Recommendations
Update the firmware to a version later than 2.90(ABTQ.1)C0.
Fix
RCE
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gs1900-48Hpv2