Description
An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication.
Published: 2026-08-04
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Zyxel WAX650S firmware contains an improper authentication flaw in the social_login.cgi CGI program. An attacker who can reach the WLAN can exploit this weakness to bypass the captive‑portal authentication mechanism and gain network access. The issue is a classic CWE-287 Improper Authentication vulnerability. Because the attacker can authenticate as any user, the flaw can lead to unauthorized access, potential data exposure, or further lateral movement on the local network.

Affected Systems

Zyxel WAX650S access points running firmware versions through 7.10(ABRM.4)C0. All earlier builds are affected.

Risk and Exploitability

The CVSS score of 6.5 reflects a moderate severity. EPSS data is currently unavailable, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local wireless; an adversary on the WLAN can trigger the vulnerable CGI endpoint to bypass authentication. If exploited in a high‑confidentiality environment, the risk of unauthorized network access is significant, though the vulnerability requires proximity to the wireless network.

Generated by OpenCVE AI on August 4, 2026 at 20:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WAX650S firmware to the latest available version to eliminate the social_login.cgi authentication flaw.
  • If a firmware upgrade is not immediately possible, restrict or disable the social_login.cgi endpoint to prevent unauthenticated access.
  • Segment WLAN traffic and enforce strong captive‑portal authentication, ensuring that clients cannot communicate with the network until credentials are verified.

Generated by OpenCVE AI on August 4, 2026 at 20:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Improper Authentication in Zyxel WAX650S Captive Portal

Tue, 04 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Zyxel
Zyxel wax650s Firmware
Vendors & Products Zyxel
Zyxel wax650s Firmware

Tue, 04 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Description An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication.
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Zyxel Wax650s Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Zyxel

Published:

Updated: 2026-08-04T18:46:57.004Z

Reserved: 2026-05-14T03:49:26.094Z

Link: CVE-2026-8508

cve-icon Vulnrichment

Updated: 2026-08-04T18:46:52.223Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-04T03:16:26.023

Modified: 2026-08-04T19:16:55.117

Link: CVE-2026-8508

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T20:45:03Z

Weaknesses