HomeSecurityCVE-2026-8508: Zyxel WAX650S exposes captive portal to authentication bypass

CVE-2026-8508: Zyxel WAX650S exposes captive portal to authentication bypass

CVE -2026-8508 affects the Zyxel WAX650S and other wireless access points, allowing an attacker already on the WLAN to bypass captive portal authentication. The vulnerability affects the CGI program social_login.cgi and requires immediate attention from corporate network administrators.

The issue is not a simple connection glitch. In a network that uses a captive portal to control guest access, the bypass can give a logged-in user access without completing the intended steps. Zyxel's official announcement confirms that fixes have been released.

See also: CaptiveCrunch: Midnight Blizzard attack on hotel Wi-Fi

What does CVE-2026-8508 mean for captive portal and WAX650S?

The vulnerability is classified as an incorrect authentication. The NVD states that the flaw is in the handling of social_login.cgi. The attacker must be on the same wireless network, but does not need to have previously completed the captive portal authentication.

For the WAX650S, firmware versions 7.10(ABRM.4)C0 and earlier. Zyxel lists 7.12(ABRM.0)C0. The same CVE also covers other models in the NWA, WAX, WBE, FWA7 and Security Routers series, so organizations should not limit their testing to a single access point.

The CVE Alert reports a CVSS score of 6.5, which is medium severity, because the attack requires a presence on the WLAN. However, the operational risk depends on how the network is designed. In hotels, offices, educational institutions, or facilities with shared Wi-Fi, it can be relatively easy to break into the wireless segment.

Vulnerability Detail CVE-2026-8508 on Zyxel WAX650S

How CVE-2026-8508 can be exploited

Bypassing does not in itself amount to remote code execution. However, it removes a critical authentication threshold and may allow access to services or resources that the captive portal was intended to restrict. The ultimate impact depends on client isolation rules, VLANs, and network policies.

Administrators should review logs for unusual login attempts, consecutive redirects, or successful sessions without a corresponding authentication entry. It is also useful to check whether guest access is actually limited to the Internet or whether it can communicate with internal management systems.

See also: Hotel Wi-Fi and DNS attacks: How Microsoft 365 accounts are stolen

Bypassing captive portal on a wireless network

Firmware update and immediate measures

The basic action is to upgrade the WAX650S to version 7.12(ABRM.0)C0 or later, after first confirming compatibility and obtaining a copy of the configuration. Zyxel recommends installing available patches for models that remain within the support period. Where required, the update should be done within a controlled maintenance window.

Until the upgrade is complete, organizations can temporarily restrict use of the captive portal, more strictly isolate guests, and disable management services from the WLAN. Management panels should not be exposed on the guest network, and administrator accounts require unique passwords and multi-factor protection.

Because the vulnerability is at the access point level, upgrading a single system is not enough when there are identical installations on different floors or branches. The IT team must compare versions from the central console, confirm that backups are available, and record which access points are providing guest services.

After installation, a retest of the connection flow is required from a test device: the user should remain restricted until they successfully complete authentication. This test, along with a check of VLANs and firewall rules, helps to determine whether the update closed the gap and whether there are no parallel paths to the internal network.

The same Zyxel announcement also separately mentions CVE-2026-6837, a command injection vulnerability in certain firmware. The WAX650S is also listed in the relevant table, with the same patch version 7.12(ABRM.0)C0. Thus, the update offers a double benefit and reduces the possibility of a second issue remaining active on the same model.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Security managers should keep the version information, installation date, and related logs for the changelog. If suspicious sessions are detected, active connections should be revoked, administrator passwords changed, and devices connected to the WLAN before the update should be investigated.

See also: Zyxel fixes critical vulnerability in routers

Firmware update to protect against CVE-2026-8508

CVE -2026-8508 shows that even a medium-score vulnerability can have practical significance when located at the access control point of a shared network. The SecNews technical team recommends immediately inventorying the affected models, installing the patched version, and reassessing guest isolation.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS