
CVE-2026-8508: authentication bypass in Zyxel Research identified an authentication bypass in the Zyxel WAX650S portal, tracked as CVE-2026-8508 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-8508). The "/cgi-bin/social_login.cgi" scenario is accessible before authentication and accepts the browser-supplied fields "fb_user", "fb_locale", "fb_age" and "fb_gender" without server-side validation of a Facebook token, OAuth code, or other proof of identity. Exploitation requires no prior privileges or account: an attacker only needs to send a crafted POST request with the "fb_user" field. The device issues an "authtok" cookie and admits the client to a guest session; Zyxel also linked the issue to downstream authorization logic and station replication. The advisory lists 39 affected models of access points and FWA7 devices, as well as the USG LITE 60AX router. Article: https://minanagehsalalma.github.io/zyxel-social-login-bypass-cve-2026-8508/ #dbugs_attacks
Post summary
The post discloses an authentication bypass in Zyxel devices, details how a crafted POST can bypass authentication, and lists impacted models, but provides no PoC, patch, or evidence of active exploitation.






