SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-8508

MEDIUM · CVSS 6.5 EPSS 0.70%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-09-03

CyberRota Analysis

AI-Generated

An improper authentication vulnerability in the "social_login.cgi" CGI program of Zyxel WAX650S firmware versions up to 7.10(ABRM.4)C0 allows attackers on the WLAN to bypass captive portal authentication. This could enable unauthorized access to network resources, potentially compromising sensitive data and network integrity. Organizations using affected firmware should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-8508
Severity
MEDIUM
CVSS
6.5
EPSS
0.70%

Original NVD Description

An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication.