CVE-2026-8508
An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication.
- Affected products
- Wax650S
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.5% (43th percentile)
- Weakness
- CWE-287
- NVD status
- Awaiting Analysis
- Published
- 2026-08-04
CVE-2026-8508 at NVD
1 known exploit for CVE-2026-8508
Proof-of-concept code and exploit modules indexed by Sploitus