Improper Authentication Vulnerability in Zyxel WAX650S Firmware
CVE-2026-8508
6.5MEDIUM
What is CVE-2026-8508?
An improper authentication flaw exists in the 'social_login.cgi' CGI program within Zyxel WAX650S firmware, allowing attackers connected to the WLAN to bypass captive portal authentication protocols. This vulnerability could enable unauthorized access to network resources, posing a significant risk to network security.
Affected Version(s)
WAX650S firmware <= 7.10(ABRM.4)C0