Chinese Hackers Exploit ZyXEL Switch Vulnerability
A critical security flaw in ZyXEL switches has been leveraged by a Chinese hacking group to exfiltrate sensitive data across 48 countries.

Global Exploitation of ZyXEL Infrastructure
A sophisticated Chinese threat actor has targeted and compromised nearly 1,000 ZyXEL GS1900 switches, according to recent findings from threat intelligence firm GreyNoise. The breach centers on CVE-2026-7273, a critical security defect carrying a CVSS score of 8.8. As reported by SecurityWeek, this vulnerability has facilitated the unauthorized exfiltration of sensitive information, including network configurations and hashed root credentials, from devices located across 48 different countries.
The vulnerability is defined as a stack-based buffer overflow, which enables unauthenticated remote attackers to execute operating system commands by sending crafted HTTP requests to the target hardware. While ZyXEL proactively released security updates to address this issue across ten distinct GS1900 switch models as early as June, the recent wave of exploitation suggests that many organizations remain exposed.
Technical Scope of the Attack
The malicious campaign, which reached a peak in August, relied on a heavily obfuscated Python script designed to harvest data from vulnerable firmware versions. GreyNoise noted that although the script was specifically configured to target firmware versions 2.10 through 2.90 on the GS1900-24 model, it contained flexible command-line options. These settings allowed the attackers to adapt their tactics to target other firmware versions currently in scope for the vulnerability, including fields for global offsets and libc base addresses.
Perhaps more concerning than the software flaw itself is the state of device security in the field. Investigators discovered that 564 of the 996 compromised switches were utilizing factory default credentials. This oversight significantly reduced the effort required for the threat actors to maintain persistence and gather deep system information, leaving these networks vulnerable to ongoing and future unauthorized access.
Regulatory Response and CISA Intervention
In response to the severity of these attacks, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-7273 to its Known Exploited Vulnerabilities (KEV) catalog this Monday. Under the requirements of BOD 26-04, federal agencies are now mandated to remediate the flaw within a three-day window to prevent further exploitation. This proactive measure reflects the agency's commitment to mitigating risks associated with active campaigns that have been
The urgency of this directive is underscored by the broader activities attributed to the same threat group. Beyond the ZyXEL campaign, the attackers have been observed utilizing a chain of vulnerabilities within Ubiquiti products to achieve remote code execution. They have also actively targeted WordPress installations, extending their reach into small business sectors and government entities alike. According to official records,
Attribution and Broader Campaign Connections
Security researchers have identified a pattern of activity that links this group to broader regional campaigns. GreyNoise has suggested that the threat actor is likely the same as, or closely affiliated with, the entity known as
The Red Heron group has been previously documented by Acronis for its role in exploiting Gitea flaws to deploy rootkits across hundreds of systems worldwide. The most significant incident involving the current ZyXEL-targeting actor involved the theft of over 18,000 sensitive records from the backend database of a Western governmental organization. As organizations worldwide assess their infrastructure, the necessity for robust patch management and the retirement of default credentials has never been more evident.
Sources
- SecurityWeekRecent ZyXEL Switch Vulnerability Exploited by Chinese Hackers