CVE-2026-8508: An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypa
An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-8508
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-8508 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for An improper authentication
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-67610: OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic …nvd · 2026-08-03
- mediumCVE-2026-18610: A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the …nvd · 2026-08-03
- mediumCVE-2026-67294: FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer ce…nvd · 2026-08-01
- unknownCVE-2025-67650: An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scrip…nvd · 2026-07-31
- criticalCVE-2026-18245: Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 migh…nvd · 2026-07-30
- highCVE-2026-12945: IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate othe…nvd · 2026-07-30
More from NVD Recent CVEs
- highCVE-2026-6837: A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel …2026-08-04
- mediumCVE-2026-18720: A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown co…2026-08-04
- mediumCVE-2026-17614: A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileReposito…2026-08-04
- mediumCVE-2026-18719: A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the fil…2026-08-04
- mediumCVE-2026-58045: A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion …2026-08-04