nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-8508 CVE-2026-8508
MEDIUM
Zyxel WAX650S Firmware Improper Authentication in social_login.cgi Allows Captive Portal Bypass
Record summary
CVE-2026-8508 has a selected CVSS score of 6.5 (medium).
Description
An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 4, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WAX650S firmwareBrowse Zyxel / WAX650S firmwareDefault status: unaffected | CVE List | <= 7.10(ABRM.4)C0 | affected |
References
2zyxel.comVendor advisory
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-improper-authentication-vulnerabilities-in-certain-aps-fwa7-and-security-routers-08-04-2026