PT-2026-67634 · Zyxel · Wax650S
CVE-2026-8508
·
Published
2026-08-04
·
Updated
2026-09-03
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Zyxel WAX650S versions prior to 7.10(ABRM.4)C0
Description
An improper authentication issue exists in the "social login.cgi" CGI program. This flaw allows an attacker connected to the WLAN to bypass captive portal authentication.
Recommendations
Update Zyxel WAX650S to a version newer than 7.10(ABRM.4)C0.
As a temporary mitigation, restrict access to the "social login.cgi" program.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wax650S