Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3436 articles · 210641 vulns · 37/41 feeds (7d)
← Back to list
6.5
CVE-2026-8508PATCHED
zyxel · wax650s firmware

CVE-2026-8508: An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions throug

Description

An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication.

Affected Products

VendorProductVersions
zyxelwax650s firmware<= 7.10(ABRM.4)C0

References

  • https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-improper-authentication-vulnerabilities-in-certain-aps-fwa7-and-security-routers-08-04-2026(vendor-advisory)

Related News (4 articles)

Tier B
CERT-FR6d ago
Bulletin d'actualité CERTFR-2026-ACT-037 (31 août 2026)
→ No new info (linked only)
Tier E
Reddit r/netsec11d ago
CVE-2026-8508: Trust-Boundary Bypass in Zyxel social_login.cgi Facebook Identity Handling
→ No new info (linked only)
Tier E
Reddit r/cybersecurity11d ago
CVE-2026-8508: Captive-Portal Social-Login Bypass Affecting 39 Zyxel Access Point Models with full firmware emulation guide
→ No new info (linked only)
Tier C
VulDB32d ago
CVE-2026-8508 | Zyxel WAX650S up to 7.10(ABRM.4)C0 Captive Portal social_login.cgi improper authentication
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.16.5 MEDIUM
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-improper-authentication-vulnerabilities-in-certain-aps-fwa7-and-security-routers-08-04-2026
CWECWE-287
PublishedAug 4, 2026
Trending Score21
Source articles4
Independent4
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-6837
CVE-2026-6837: A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions
Trending: 6
CRITICALCVE-2026-13206
Multiple Vulnerabilities in Zyxel's WAH7601 - OS Command Injection
Trending: 3
HIGHCVE-2026-6374
Hardcoded Credentials in Zyxel WAH7601 Router
Trending: 2
HIGHCVE-2026-12984
Exposure of Sensitive Information to an Unauthorized Actor in Zyxel's WAH7601
Trending: 2
HIGHCVE-2026-14818
CVE-2026-14818: A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versi
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 4, 2026
Discovered by ZDM
Aug 4, 2026
Patch Available
Aug 4, 2026