Junglewise Threat Intelligence

CVE-2026-8508: Zyxel WAX650S improper authentication in social_login.cgi

CVE-2026-8508 · Severity: medium · CVSS 6.5 · Published 2026-08-04

Vendors: Zyxel.

Executive brief

The Zyxel WAX650S is a wireless access point used to provide network connectivity. A flaw in its web authentication mechanism allows attackers on the local wireless network to bypass the captive portal, gaining unauthorized network access without proper credentials. This could enable attackers to access network resources and internal systems intended to be restricted.

Technical details

An improper authentication vulnerability exists in the "social_login.cgi" CGI program in Zyxel WAX650S firmware through version 7.10(ABRM.4)C0. The vulnerability allows attackers on the WLAN to bypass captive portal authentication through improper input validation or authentication checks in the social login handler. No user interaction or prior authentication is required; an attacker simply needs network access to the wireless network. An attacker can exploit this to bypass the access control mechanism and gain unrestricted network access. Patches are available in firmware version 7.12(ABRM.0)C0 and later.

Affected products

  • Zyxel WAX650S through 7.10(ABRM.4)C0

Timeline

  • 2026-08-04: disclosed

References

Related threats