Back www.zyxel.com Zyxel Security Advisory For Stack Based Buffer Overflow Vulnerability In Gs1900 Series Switches 06 16 2026
Zyxel has released patches for GS1900 series switches affected by a stack-based buffer overflow vulnerability. Users are advised to install them for optimal protection.
A stack-based buffer overflow vulnerability in the CGI program of the Zyxel GS1900 series switch firmware could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
After a thorough investigation, we identified the vulnerable switch firmware versions and released patches for models still within their vulnerability support period, as shown in the table below. Please note that on-market products not listed in the table remain unaffected.
Please your local service rep or visit Zyxel's Community for further information or assistance.
Thanks to Lei Gu, Jun Cao, Zhiqing Rui, Jingzheng Wu, and Tianyue Luo from ISCAS for reporting the issue to us.
2026-6-16: Initial release
We are always here to help!
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
