Cybersecurity

996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24

Published 2 min readBy NewUJ Editorial Desk

Updated new information added

996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
Photo: Sinchen.Lin, Wikimedia Commons, CC BY 2.0
0 0
XWhatsAppTelegramLinkedIn

Nearly a thousand internet-facing Zyxel network switches have been quietly stripped of their credentials and configuration files, and the US government's patch deadline for the flaw behind it falls on 24 September.

The bug is CVE-2026-7273, a stack-based buffer overflow in the CGI program of Zyxel's GS1900 line of smart managed switches — the inexpensive 8- to 48-port boxes that sit in small offices, school closets and branch racks. Zyxel scores it 8.8 out of 10 on the CVSS scale, according to the National Vulnerability Database: a LAN-based attacker with no credentials at all can send a crafted HTTP request and run operating-system commands on the device.

Security firm GreyNoise says a suspected Chinese-speaking threat actor has been weaponising it since on or about 17 August 2026, and had successfully exploited and exfiltrated data from 996 Zyxel switches across 48 countries by the time it published on 22 September. The haul included device configuration files, network information and hashed root-level credentials — material that maps a victim's internal network and can be cracked offline. The exploit arrived as a Python script heavily obfuscated with the commercial tool PyArmor, which then used TFTP to fetch and run a custom collector script, The Hacker News reported. Italy, the United States, Taiwan, France and South Korea are among the countries hit. Researchers describe a possible overlap with a cluster tracked as Red Heron, but stop short of firm attribution.

Why now: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 21 September 2026 and set 24 September as the remediation due date. That deadline is binding on US federal civilian executive branch agencies under Binding Operational Directive 26-04; every other organisation is encouraged, not ordered, to act. GreyNoise told BleepingComputer that “As of 17 September 2026, this is the first publicly documented case of exploitation in the wild of this vulnerability.”

The uncomfortable detail is the calendar. Zyxel published its advisory and fixed firmware on 16 June 2026 — two months before the campaign started — crediting Lei Gu, Jun Cao, Zhiqing Rui, Jingzheng Wu and Tianyue Luo of ISCAS with the discovery. Ten models are affected, including the GS1900-8, GS1900-16, GS1900-24 and GS1900-48; each has a patched build ending in “.2)C0”, such as 2.90(AAHN.2)C0 for the GS1900-48.

What is not known: how many of the 996 devices have since been cleaned, whether the count has grown since GreyNoise's tally, and what the stolen credentials were used for next. CISA lists any ransomware link as unknown. Anyone running a GS1900 should check the firmware build, patch it, and rotate the switch's administrative credentials.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.