important · Firmware
CISA now confirms exploitation of the unauthenticated Zyxel GS1900 CGI stack overflow.
Affects
Zyxel GS1900-series smart managed Ethernet switches running embedded switch firmware.
The documented boundary is LAN access to the management service, where a crafted HTTP request triggers the overflow. We do not know the incidents' initial network position, whether attackers obtained controlled command execution or the resulting privilege. Zyxel's fix was not reviewed for this brief, so this cannot lead.
Detail and 2 sources
Chain to watch
Reach the GS1900 CGI management service without credentials→↓Send a crafted request that triggers the stack overflow→↓Exploit the memory corruption in an outcome not yet publicly characterized→↓Public evidence does not establish controlled command execution, its privilege context or whether incidents began from internet-exposed management.
Unverified chainObtain incident-response evidence describing the initial network position and exploited outcome, or reproduce a benign command on stock firmware and record the CGI process UID.