Skip to content

CVE-2026-7273 explained: what the Zyxel GS1900 Series Switches flaw means for your business

By Donovan Brown
September 22, 2026
8 sections
CVE-2026-7273 explained: what the Zyxel GS1900 Series Switches flaw means for your business — Cyber Security article cover card from LayerLogix, with a warning alert icon
01

Introduction

CVE-2026-7273 is a security flaw in Zyxel GS1900 Series Switches, the network switches many small offices use to connect computers, phones, and Wi-Fi access points. It lets someone already on your local network take over the switch without a password. If you run one of these switches, keep reading.

02

Does this affect you?

The two-minute check

  1. Look at the label on the switch, or its web management page, for the model name.
  2. Confirm whether the model is a GS1900-48HPv2. The record describes this flaw for that model line.
  3. Check the firmware version in the switch's web interface. The record lists affected firmware as versions through 2.90(ABTQ.1)C0 (NVD).

When you can stop reading

If you don't run any Zyxel GS1900 Series Switches, this flaw does not apply to you. Close the tab. The record names only this product line, and it does not describe any other Zyxel switch or any other vendor's equipment.

03

How bad is it, honestly?

What the official record says

The National Vulnerability Database (NVD) scores this flaw 8.8 out of 10, rated HIGH, under Common Vulnerability Scoring System (CVSS) version 3.1 (NVD). The scoring details show the attacker needs to already be on your local network. No password and no click from anyone else are required. From there, they can send a crafted web request to the switch's management program and run commands on it directly.

This flaw is also on the CISA Known Exploited Vulnerabilities (KEV) catalog, which means it is already being used in real attacks (CISA).

The Exploit Prediction Scoring System (EPSS) puts the probability of exploitation in the next 30 days at 0.32%, in the 24.6th percentile of all scored flaws (FIRST.org). That is a low chance of exploitation in the next 30 days; EPSS is a forecast of near-term activity, not a measure of how bad the flaw is.

What that means for a business like yours

In practice, anyone who gets onto your local network can potentially take control of this switch. That could be a compromised laptop, a rogue device on Wi-Fi, or a visitor who plugged in. Once someone controls the switch, they control the path in and out for everything connected to it.

04

What to do about it, step by step

If someone else manages your IT

Send your provider a short message. Ask them to confirm this in three parts.

  • "Do we run any Zyxel GS1900 Series Switches, especially GS1900-48HPv2?"
  • "Have you checked our switches against CVE-2026-7273?"
  • "Can you restrict management access to these switches until Zyxel publishes new guidance?"

If you don't have a dedicated IT partner, LayerLogix's managed IT services team can take this off your plate.

If you manage it yourself

  1. Open the switch's web management page from a browser on your local network.
  2. Find the model name and firmware version, usually on the status or system page.
  3. Compare the model to GS1900-48HPv2 and the firmware to the range in the record.
  4. If it matches, limit who can reach the management page.
  5. Restrict management access to a single trusted computer.
  6. Change the switch's admin password if you have not changed it recently.
  7. Check the vendor's advisory page for any new guidance (Zyxel advisory).
05

How long you have

This flaw is already on the CISA Known Exploited Vulnerabilities (KEV) catalog (CISA). Federal agencies had to act on it by September 24, 2026. That deadline does not legally bind a private business. Criminals are already using this flaw, so the honest answer is: now.

06

How to check it actually worked

The record lists no fixed version to update to, so there is no update screen to check yet. What you can confirm is your own exposure. Log back into the switch and verify management access is limited to your trusted device. Confirm the admin password has actually changed. Watch the vendor's advisory page for a version update, and re-check there once one appears.

07

What to do if you can't patch right now

There is no patch to install yet, so every option here is about reducing exposure until Zyxel names one. Restricting management access to a single trusted device keeps most casual attackers off the switch's web interface. It does not stop someone who is already on that trusted device. Separating the switch's management traffic onto its own network segment, sometimes called a management VLAN, keeps ordinary office traffic away from the administrative interface. Turning off remote or wireless access to the management page removes one more path in. It still won't help if the attacker is already inside your network.

A tool such as a privileged access management service can also help limit who holds admin credentials to network gear like this switch. Broader network monitoring, through a service like managed cybersecurity, can flag unusual traffic to the switch even before a fix exists.

08

Frequently Asked Questions

Do I have to do anything if we only use this switch at home?

The record does not distinguish between home and office use. If the switch matches the affected model and firmware, the same exposure applies wherever it sits on your network.

Will restricting management access break anything?

Restricting access usually just means reaching the switch's settings page from one chosen computer. Normal traffic through the switch's ports keeps working. Only the administrative login changes.

Does this affect other Zyxel switches we own?

The record names only GS1900 Series Switches, specifically the GS1900-48HPv2 firmware line. It does not describe any other Zyxel model, so treat other switches as outside this record until Zyxel says otherwise.

How do we know when Zyxel releases a fix?

Check the vendor's advisory page for updates (Zyxel advisory). The record does not currently list a fixed version, so watch that page rather than guessing.

Should we just replace the switch?

That is a decision for your budget and risk tolerance, not something the record can answer on its own. If you want help weighing it, a free IT assessment can walk through your options with you.

LayerLogix brings 20+ years of experience and 100% Texas-based support to businesses across The Woodlands, Round Rock, Greater Houston, DFW, and Austin. If this switch is sitting on your network right now, contact us and we'll help you sort out the exposure before it becomes a bigger problem.

Back to Blog
Keep Reading

Related Articles

Need Expert IT Support?

Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.

Call NowBook a Call