What Happened
CISA added CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 series switches enabling arbitrary operating-system command execution, to its Known Exploited Vulnerabilities catalog on September 21 and gave federal agencies three days to remediate under Binding Operational Directive 26-04. Researchers tracking the exploitation attribute it to a suspected Chinese-speaking actor running a heavily obfuscated Python script to pull hashed root credentials, network information, and configuration details from compromised switches. The campaign reached 996 devices across 48 countries, concentrated in Italy, the United States, Taiwan, and South Korea. Some 564 of the compromised switches were still configured with factory-default credentials, a separate and avoidable weakness the attacker exploited alongside the software flaw itself. Read more from Help Net Security.
Why This Matters for Canadian Organizations
GS1900 series switches sell into small-business and mid-market networks widely, a segment of the Canadian economy the Canadian Centre for Cyber Security has flagged repeatedly as underprepared relative to enterprise and government targets. Compromised switch-level credentials give an attacker visibility into network topology and a foothold for further lateral movement, and more than half the compromised devices running out-of-the-box passwords points to a basic hygiene gap rather than an unavoidable flaw. Canadian retailers, clinics, and municipal offices running unmanaged or lightly managed network hardware face the same exposure documented in this campaign, with no equivalent domestic three-day mandate forcing remediation outside the federal government.
What to Do
Organizations running Zyxel GS1900 switches should apply the vendor’s fix immediately and change any default administrative credentials still in place, regardless of patch status. Network teams should audit switch inventories for internet-facing management interfaces, since exposure to the public internet is a precondition for this style of attack, and restrict management access to internal, segmented networks wherever the deployment allows it. Given the attacker’s use of a single script across a dozen unrelated product vulnerabilities, security teams should treat this less as an isolated Zyxel issue and more as evidence of an active, opportunistic scanning operation working through internet-exposed network hardware broadly.






