Impact
The Zyxel WAX650S firmware contains an improper authentication flaw in the social_login.cgi CGI program. An attacker who can reach the WLAN can exploit this weakness to bypass the captive‑portal authentication mechanism and gain network access. The issue is a classic CWE-287 Improper Authentication vulnerability. Because the attacker can authenticate as any user, the flaw can lead to unauthorized access, potential data exposure, or further lateral movement on the local network.
Affected Systems
Zyxel WAX650S access points running firmware versions through 7.10(ABRM.4)C0. All earlier builds are affected.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity. EPSS data is currently unavailable, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local wireless; an adversary on the WLAN can trigger the vulnerable CGI endpoint to bypass authentication. If exploited in a high‑confidentiality environment, the risk of unauthorized network access is significant, though the vulnerability requires proximity to the wireless network.
OpenCVE Enrichment