An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication.
History

Tue, 04 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Zyxel
Zyxel wax650s Firmware
Vendors & Products Zyxel
Zyxel wax650s Firmware

Tue, 04 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Description An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication.
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zyxel

Published:

Updated: 2026-08-04T01:57:51.770Z

Reserved: 2026-05-14T03:49:26.094Z

Link: CVE-2026-8508

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:30:03Z