Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Chinese Hackers Exploit ZyXEL Switch Flaw to Steal Data From Nearly 1,000 Devices

Chinese hackers exploit a ZyXEL switch flaw to steal sensitive data from nearly 1,000 devices, prompting urgent patching warnings.

 

A Chinese threat actor has been using the recently discovered vulnerability in ZyXEL GS1900 switches to steal crucial information from the devices around the world, according to GreyNoise, a threat intelligence company.

The vulnerability, tracked as CVE-2026-7273, has a CVSS score of 8.8 and is a stack-based buffer overflow, enabling a remote unauthenticated attacker to execute OS commands via a specially crafted HTTP request. 

ZyXEL has issued security updates for ten GS1900 switch models in June. However, according to GreyNoise, the flaw was actively exploited in August, targeting the devices in 48 countries. The threat actors used a Python script, which was significantly obfuscated to hide its purpose, to extract the hashes of the root credentials, configuration, and network information from 996 affected switches. 

While the script targeted the GS1900-24 switches with firmware versions 2.10 to 2.90, some of the command-line options in the script contained values related to libc base addresses and global offsets. Therefore, it might be possible that the threat actors could use the same vulnerability to target other firmware versions. The information stolen from the switches also showed that 564 devices were using default credentials. This lets the attackers effortlessly compromise these devices. 

On Monday, the US Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog. Also, per the Binding Operational Directive 26-04, all federal agencies must remediate this issue within 3 days of its publication. GreyNoise also reported that the same threat actor conducted Ubiquiti attacks, which involved exploiting the zero-day flaws to gain remote access and execute arbitrary code in the devices. 

In addition, the attackers used exploits targeting WordPress flaws to launch attacks against small businesses and government entities in July. The attacks entailed a threat actor compromising a Western government organization, stealing over 18000 sensitive documents from the agency’s backend database, and publishing the results on a Matrix communication service. 

However, the cybersecurity firm is yet to confirm if any of these attacks were conducted by the same threat actor. Acronis, another cybersecurity firm, previously identified threat actors using the Red Heron hacking group, which primarily used Gitea’s zero-day flaw to target more than 100 organizations worldwide.
Share it:

Chinese Hackers

Critical Flaws

Data Breach

data security

data stealing

data vulnerability

Hacker attack