CVE-2026-8508: authentication bypass in Zyxel
Attack Techniques & Methods2026-09-03, 09:06
Research identified an authentication bypass in the Zyxel WAX650S portal, tracked as CVE-2026-8508. The
/cgi-bin/social_login.cgi scenario is accessible before authentication and accepts the browser-supplied fields fb_user, fb_locale, fb_age and fb_gender without server-side validation of a Facebook token, OAuth code, or other proof of identity.Exploitation requires no prior privileges or account: an attacker only needs to send a crafted POST request with the
fb_user field. The device issues an authtok cookie and admits the client to a guest session; Zyxel also linked the issue to downstream authorization logic and station replication. The advisory lists 39 affected models of access points and FWA7 devices, as well as the USG LITE 60AX router.Vulnerabilities
Vendors
Products