Skip to content
VulniPulse

Zyxel Switches (GS-series) Vulnerabilities & Security Advisories

2 advisories tracked · Zyxel Security Advisories via NVD · 1 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Zyxel advisory that VulniPulse classified as Switches (GS-series), with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 1 high, 1 medium.

Android app · Google Play

Monitor Zyxel CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Zyxel Security Advisories via NVD

Zyxel runs its own CNA (security@zyxel.com.tw), but a large share of Zyxel CVEs are assigned by MITRE and third-party researchers — so VulniPulse ingests them from NVD by keyword (which covers more than the CNA feed alone), requiring a Zyxel product in the description, and links back to the zyxel.com security advisory when referenced. Covers the USG FLEX / ATP / VPN firewalls, Nebula-managed access points, the GS-series switches and the VMG/EMG gateways — an SMB fleet that is a chronic KEV / actively-exploited target.

Latest Zyxel Switches (GS-series) advisories

High8.8Zyxel Exploited CISA KEV

High [CVE-2026-7273] stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. Affected products named by the advisory: GS1900-8 firmware; GS1900-8HP firmware; GS1900-10HP firmware; GS1900-16 firmware; and 3 more. Affected products named by the advisory: GS1900-24 firmware; GS1900-24E firmware; GS1900-24EP firmware.

CVE-2026-7273
Switches (GS-series)
Jun 16, 2026
Medium6.5Zyxel

Medium [CVE-2026-4795] missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware versions through 1.00(ACPT.2)C0, GS1200-5HPv3 firmware versions through 1.00(ACPU.2)C0, GS1200-8HPv3 firmware versions through 1.00(ACPV.2)C0, and GS1200-10v3 firmware versions through 1.00(ACPW.2)C0 could allow a LAN-based, unauthenticated attacker to read the system configuration from a log file via a crafted HTTP request

A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware versions through 1.00(ACPT.2)C0, GS1200-5HPv3 firmware versions through 1.00(ACPU.2)C0, GS1200-8HPv3 firmware versions through 1.00(ACPV.2)C0, and GS1200-10v3 firmware versions through 1.00(ACPW.2)C0 could allow a LAN-based, unauthenticated attacker to read the system configuration from a log file via a crafted HTTP request.

CVE-2026-4795
Switches (GS-series)
May 26, 2026

← All Zyxel advisories