CVE-2026-8508: Medium severity Zyxel Wax650s Firmware vulnerability
An improper authentication vulnerability in the "sociallogin.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zyxel WAX650S firmwareto a version that resolves this vulnerability.Fixed in 7.10(ABRM.4)C0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8508?
The severity of CVE-2026-8508 is medium with a score of 6.5.
How does CVE-2026-8508 affect Zyxel WAX650S firmware?
CVE-2026-8508 allows an attacker on the WLAN to bypass captive portal authentication in Zyxel WAX650S firmware.
What versions of Zyxel firmware are impacted by CVE-2026-8508?
Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 are impacted by CVE-2026-8508.
How can an organization mitigate CVE-2026-8508?
To mitigate CVE-2026-8508, organizations should update their Zyxel WAX650S firmware to a version that addresses the vulnerability.
What type of vulnerability is CVE-2026-8508 classified as?
CVE-2026-8508 is classified as an improper authentication vulnerability.