CVE-2026-8508: authentication bypass in Zyxel

Research identified an authentication bypass in the Zyxel WAX650S portal, tracked as CVE-2026-8508. The /cgi-bin/social_login.cgi scenario is accessible before authentication and accepts the browser-supplied fields fb_user, fb_locale, fb_age and fb_gender without server-side validation of a Facebook token, OAuth code, or other proof of identity.
Exploitation requires no prior privileges or account: an attacker only needs to send a crafted POST request with the fb_user field. The device issues an authtok cookie and admits the client to a guest session; Zyxel also linked the issue to downstream authorization logic and station replication. The advisory lists 39 affected models of access points and FWA7 devices, as well as the USG LITE 60AX router.
Vulnerabilities
6.5
CVE-2026-8508
Vendors
Zyxel
Products
Access Points
Fwa7 Devices
Social_Login.Cgi
Usg Lite 60Ax
Wax650S