Note
The factory password left with the config
The exploit is not the embarrassing part. The password that shipped in the box is.
GreyNoise says a suspected Chinese-speaking operator reached 996 Zyxel GS1900 switches in 48 countries and pulled configs, network detail, and hashed root credentials. CVE-2026-7273 is a stack overflow in the management CGI: no login, if you can hit the interface. Zyxel shipped firmware for ten GS1900 models on 16 June. CISA put it on the KEV list Monday and told civilian federal agencies to be done by Thursday.
Of those 996, GreyNoise says 564 still had the factory default credentials. The hash left anyway. The default means the next person does not even need the hash.
What “we patched in June” does not cover
June is when the file existed. September is when 996 management planes were still old enough to answer. A switch in a closet, a branch, an ISP handoff, does not appear in the laptop EDR queue. Nobody rebooted it because a Group Policy told them to. It sits there with the admin page on a routable address and the login from the quick-start card.
Hashed root plus a running config is a map: VLANs, management hosts, the password you were supposed to have changed in 2019. Factory default on more than half of them means a chunk of that map is not even a cracking job.
What to pull before Thursday
Inventory GS1900s that can be reached from anywhere that is not a console cable. Firmware newer than the June build. Change the root even if you think you changed it. Assume any switch that answered in August has had its config copied. The federal deadline is a calendar fact for civilian agencies. Everyone else with a GS1900 on the internet is on the same list.
If your IR firm is hunting malware on the file server, ask them who can still log into the switch with the password on the sticker. That sticker is the incident.
Cite: Fabio Correia, “The factory password left with the config”, 2026-09-23. https://www.fabiocti.com/notes/the-factory-password-left-with-the-config/. Markdown: https://www.fabiocti.com/notes/the-factory-password-left-with-the-config.md
Comments
Public thread on the canonical URL. GitHub login keeps this off a spam hole; replies are copied here on the next build so crawlers and models see them in the HTML.
No public replies yet.
Add a comment