Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3666 articles · 197852 vulns · 37/41 feeds (7d)
← Back to list
6.5
CVE-2026-8508PATCHED
zyxel · wax650s firmware

CVE-2026-8508: An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions throug

Description

An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication.

Affected Products

VendorProductVersions
zyxelwax650s firmware<= 7.10(ABRM.4)C0

References

  • https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-improper-authentication-vulnerabilities-in-certain-aps-fwa7-and-security-routers-08-04-2026(vendor-advisory)

Related News (3 articles)

Tier E
Reddit r/netsec1d ago
CVE-2026-8508: Trust-Boundary Bypass in Zyxel social_login.cgi Facebook Identity Handling
→ No new info (linked only)
Tier E
Reddit r/cybersecurity1d ago
CVE-2026-8508: Captive-Portal Social-Login Bypass Affecting 39 Zyxel Access Point Models with full firmware emulation guide
→ No new info (linked only)
Tier C
VulDB22d ago
CVE-2026-8508 | Zyxel WAX650S up to 7.10(ABRM.4)C0 Captive Portal social_login.cgi improper authentication
→ No new info (linked only)
CVSS 3.16.5 MEDIUM
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-improper-authentication-vulnerabilities-in-certain-aps-fwa7-and-security-routers-08-04-2026
CWECWE-287
PublishedAug 4, 2026
Trending Score34
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-6837
CVE-2026-6837: A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions
Trending: 18
CRITICALCVE-2026-13206
Multiple Vulnerabilities in Zyxel's WAH7601 - OS Command Injection
Trending: 7
HIGHCVE-2026-12984
Exposure of Sensitive Information to an Unauthorized Actor in Zyxel's WAH7601
Trending: 6
HIGHCVE-2026-6374
Hardcoded Credentials in Zyxel WAH7601 Router
Trending: 5
HIGHCVE-2026-14818
CVE-2026-14818: A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versi
Trending: 4

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 4, 2026
Discovered by ZDM
Aug 4, 2026
Patch Available
Aug 4, 2026