news.mlab.sh
Back to the feed
vulnerability

Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers

HighCVSS 8.8
Summary

A Chinese hacking group, linked to the Red Heron group, has been exploiting a vulnerability in ZyXEL GS1900 switches to steal sensitive data, including hashed credentials, from devices in 48 countries. The vulnerability, CVE-2026-7273, allows remote code execution via HTTP requests, and a significant number of devices were found with default credentials, increasing the risk of further attacks. The CISA has added the vulnerability to its KEV catalog, urging agencies to patch it immediately.

A Chinese threat actor has been actively targeting vulnerable ZyXEL GS1900 switches globally, seeking to exfiltrate sensitive information. The vulnerability, identified as CVE-2026-7273, is a stack-based buffer overflow that can be exploited without authentication, enabling attackers to execute OS commands through crafted HTTP requests. ZyXEL released security updates in June to address the bug, but GreyNoise warned on Monday that the vulnerability was being exploited since August against devices in 48 countries. The threat actor utilized a heavily obfuscated Python script to steal hashed root credentials, configuration details, and networking information from 996 vulnerable devices. Notably, 564 of the compromised devices were running with factory default credentials, significantly widening the attack surface. The CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to patch it within three days, aligning with guidance from BOD 26-04. GreyNoise further indicated that the threat actor is linked to the Red Heron group, which also exploited Ubiquiti vulnerabilities and targeted WordPress installations in July, focusing on small business and government entities. The most concerning incident involved a western governmental organization, resulting in the theft of over 18,000 sensitive records from its backend database.

Read the full article at SecurityWeek