CVE-2026-8508Disclosure

HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

7.5/ 10 priority

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 3 mentions (2026-08-04); latest day: 2
  • 7 total mentions across 4 days

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-08-04: 3Mentions · 2026-08-16: 1Mentions · 2026-08-25: 1Mentions · 2026-09-03: 2PoC Mentioned / Linked · 2026-08-04: 1PoC Mentioned / Linked · 2026-08-25: 1PoC Mentioned / Linked · 2026-09-03: 1Exploit Tool / Code · 2026-09-03: 1Active Exploitation · 2026-08-04: 1Patch / Workaround · 2026-08-04: 1Patch / Workaround · 2026-08-16: 1Patch / Workaround · 2026-09-03: 1Technical Details · 2026-08-04: 2Technical Details · 2026-08-16: 1Technical Details · 2026-08-25: 1Technical Details · 2026-09-03: 208-0408-1608-2509-03
Signal classification4 categories
Disclosure
342.9%
Patch
228.6%
Active Exploitation
114.3%
PoC
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-043
Active Exploitation1Disclosure1Patch1
2026-08-161
Patch1
2026-08-251
Disclosure1
2026-09-032
Disclosure1PoC1
Full discourse7 posts
  • dbugs@ptdbugs
    Disclosure

    CVE-2026-8508: authentication bypass in Zyxel Research identified an authentication bypass in the Zyxel WAX650S portal, tracked as CVE-2026-8508 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-8508). The "/cgi-bin/social_login.cgi" scenario is accessible before authentication and accepts the browser-supplied fields "fb_user", "fb_locale", "fb_age" and "fb_gender" without server-side validation of a Facebook token, OAuth code, or other proof of identity. Exploitation requires no prior privileges or account: an attacker only needs to send a crafted POST request with the "fb_user" field. The device issues an "authtok" cookie and admits the client to a guest session; Zyxel also linked the issue to downstream authorization logic and station replication. The advisory lists 39 affected models of access points and FWA7 devices, as well as the USG LITE 60AX router. Article: https://minanagehsalalma.github.io/zyxel-social-login-bypass-cve-2026-8508/ #dbugs_attacks

    Post summary

    The post discloses an authentication bypass in Zyxel devices, details how a crafted POST can bypass authentication, and lists impacted models, but provides no PoC, patch, or evidence of active exploitation.

    0202171.5K
    3.5K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 Zyxel cihazlarında Authentication Bypass: CVE-2026-8508 Zyxel'in bazı Access Point, FWA7 ve güvenlik router modellerinde bulunan CVE-2026-8508, captive portal üzerindeki Social/Facebook Login mekanizmasının kimlik doğrulamasını atlamaya izin veriyor. Sorunun kaynağı, /cgi-bin/social_login.cgi endpoint'inin kimlik doğrulama öncesinde erişilebilir olması ve fb_user gibi istemci tarafından gönderilen alanların sunucu tarafında geçerli bir Facebook OAuth token/kimlik kanıtıyla doğrulanmaması. Saldırgan, WLAN üzerinden crafted bir POST isteği göndererek authtok cookie'si alabiliyor ve guest oturumuna kabul edilebiliyor. 📌 CVSS: 6.5 (Medium) 📌 Etkilenen: 39 Zyxel modeli 📌 WAX650S için düzeltilmiş sürüm: 7.12(ABRM.0)C0 ⚠️ Bu bir RCE değil; temel olarak captive portal authentication bypass açığı. Ancak elde edilen oturum bilgisinin downstream authorization ve station enforcement mekanizmalarıyla ilişkili olması nedeniyle etkisi yalnızca login ekranını geçmekle sınırlı olmayabilir. Teknik analiz ve PoC: https://minanagehsalalma.github.io/zyxel-social-login-bypass-cve-2026-8508/

    Post summary

    The post announces Zyxel CVE-2026-8508, an authentication bypass on captive portals, shares a PoC link and exploitation details, and notes a patch for affected models.

    010731.3K
    2.3K followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    CVE-2026-8508: Trust-Boundary Bypass in Zyxel social_login.cgi Facebook Identity Handling https://minanagehsalalma.github.io/zyxel-social-login-bypass-cve-2026-8508/

    Post summary

    The text announces the disclosure of CVE‑2026‑8508, a trust‑boundary bypass flaw in Zyxel’s social_login.cgi, and includes a link that presumably hosts a proof‑of‑concept.

    010301.1K
    33.8K followersView on X
  • SoyNubeNegra@La_Nube_Negra
    Patch

    🛡️ Zyxel — más de 35 equipos, entre access points, gateways FWA7 y un router de seguridad, quedaron expuestos a inyección de comandos. Impacto: CVE-2026-6837 permite ejecución de comandos OS post-autenticación en 18 modelos de AP; CVE-2026-8508 permite saltarse la autenticación del portal cautivo en más de 35 equipos, incluyendo FWA7 y el USG LITE 60AX. Estado: parches ya disponibles para la mayoría de modelos, salvo el WAC500H que requiere hotfix bajo solicitud, y el USG LITE 60AX que recibe su parche recién en septiembre. Acción hoy: 1. Verifica el modelo y versión de firmware exacto contra el listado de Zyxel. 2. Actualiza a firmware 7.12 o 7.40 según corresponda al equipo. 3. Si tienes un USG LITE 60AX, restringe acceso administrativo mientras llega el parche de septiembre. Tienes inventario actualizado de qué firmware corre cada AP de tu red ahora mismo? Sigue a @smarteck_cl si te sirve este tipo de análisis. #Zyxel #CVE #Networking https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-command-injection-and-improper-authentication-vulnerabilities-in-certain-aps-fwa7-and-security-routers-08-04-2026

    Post summary

    Zyxel released a patch advisory for command injection (CVE-2026-6837) and authentication bypass (CVE-2026-8508) affecting over 35 devices, noting available firmware fixes for most models and pending updates for a few.

    0000054
    1.9K followersView on X
  • TECHEPAGES@techepages
    Patch

    🚨 CVE-2026-8508 — Zyxel WAX650S Captive Portal Auth Bypass A flaw in social_login.cgi lets an attacker already on the WLAN bypass captive portal authentication entirely — no valid login needed. CVSS 6.5 (Medium), but real-world risk is higher on shared networks (hotels, offices, schools). Also affects: NWA, WAX, WBE, FWA7 & Security Router series — not just the WAX650S. Fix: Update to firmware 7.12(ABRM.0)C0+

    Post summary

    A vulnerability in Zyxel WAX650S allows bypass of captive portal authentication; a firmware update 7.12(ABRM.0)C0+ provides the fix.

    0000040
    35 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Attention, elevated activities detected targeting Zyxel WAX650S (CVE-2026-8508) https://vuldb.com/vuln/385743/cti

    Post summary

    The post reports detected malicious activity targeting Zyxel WAX650S for CVE‑2026‑8508, suggesting that the vulnerability may be actively exploited, though no specific exploit or mitigation details are given.

    00000119
    2.3K followersView on X
  • SecNews@SecNews_GR
    Disclosure

    CVE-2026-8508: Το Zyxel WAX650S εκθέτει το captive portal σε παράκαμψη πιστοποίησης https://secn.ws/pNIQSW

    Post summary

    The text announces CVE‑2026‑8508, a vulnerability that allows authentication bypass on the Zyxel WAX650S captive portal, with additional details presumably available at the linked webpage.

    00000135
    7.0K followersView on X

Explore more