Back to Feed
Nation-stateSep 22, 2026

Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers

Chinese hackers exploit ZyXEL switch vulnerability to steal credentials and data.

Summary

A Chinese threat actor has been actively exploiting a critical vulnerability (CVE-2026-7273) in ZyXEL GS1900 switches to exfiltrate sensitive information, including hashed credentials and network configurations. The vulnerability, a stack-based buffer overflow, allows for OS command execution without authentication. GreyNoise reported that the actor used an obfuscated Python script to target nearly 1,000 devices across 48 countries, with a significant portion still using default credentials.

Full text

A Chinese threat actor has been targeting vulnerable ZyXEL GS1900 switches worldwide for sensitive information exfiltration, threat intelligence firm GreyNoise warns. Tracked as CVE-2026-7273 (CVSS score of 8.8), the security defect is described as a stack-based buffer overflow that could be exploited without authentication to execute OS commands via crafted HTTP requests. ZyXEL rolled out security updates patching the bug in ten GS1900 switch models in June. On Monday, GreyNoise warned that it was exploited by a Chinese hacking group in August against ZyXEL devices in 48 countries. The threat actor used a heavily obfuscated Python script to exfiltrate sensitive information such as hashed root credentials, configuration details, and networking information from 996 vulnerable devices. “While the script explicitly targets firmware versions 2.10-2.90 of the GS1900-24, it does provide command-line options (e.g., libc base address, global offsets) for targeting other firmware in scope for the vulnerability,” GreyNoise says. While the hackers extracted hashed credentials, 564 of the compromised devices had factory default credentials, leaving the door open to future attacks.Advertisement. Scroll to continue reading. On Monday, the US cybersecurity agency CISA added CVE-2026-7273 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days, as mandated by BOD 26-04. The same threat actor was also seen using a chain of Ubiquiti vulnerabilities leading to remote code execution (RCE), and targeting WordPress installations in July, in attacks against small business and government entities. “The most egregious data theft occurred against an identified western governmental organization involving more than 18,000 sensitive records stolen from its backend database,” GreyNoise says. The cybersecurity firm believes that the threat actor is the same as or closely related to the Red Heron hacking group that Acronis observed exploiting a Gitea vulnerability in attacks targeting hundreds of systems worldwide. Related: WordPress Patches ‘Click2Shell’ Vulnerability Related: Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities Related: In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw Related: CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire RatHat Android Trojan Uses AI for AutomationCrowdSec Confirms Source Code Stolen in Supply Chain AttackOrganizations Warned of 3 Exploited Linux Kernel VulnerabilitiesTigerByte Cyber Emerges From Stealth With $3 Million in FundingNightmareStresser DDoS Service Disrupted in International OperationBrevo Supply Chain Attack Injects Malware Into 100,000 WebsitesCritical Orkes Conductor Vulnerability Exploited in AttacksMIND Secures $72 Million for AI-Powered DLP Latest News Malicious B-tree NPM Package Accumulates Millions of DownloadsWordPress Patches ‘Click2Shell’ VulnerabilityJapan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider SchemeUS Proposes AI Incident Alert System in Talks With China, Bessent SaysGoogle Hit With $463 Million Fine for EU Location Data Rule BreachFake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ StealerCISO Conversations: Noopur Davis – The Accidental Global CISO at ComcastDragos Completes NetRise and runZero Acquisitions Following Accenture Deal Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveVeritas Capital has appointed Joel Fulton as Chief Information Security Officer.incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.Ruben D. Chacon has joined ADM as Vice President and Global CISO.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-7273
  • malware — Python script

Entities

ZyXEL (vendor)GS1900 (product)Red Heron (threat_actor)GreyNoise (vendor)CISA (vendor)