Improper Authentication in ZyXEL Communications Corp. products - CVE-2026-8508

 

Improper Authentication in ZyXEL Communications Corp. products - CVE-2026-8508

Published: August 4, 2026


Vulnerability identifier: #VU140858
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-8508
CWE-ID: CWE-287
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error when processing authentication requests in the "social_login.cgi" CGI program. A remote attacker on the local network can bypass authentication process and gain unauthorized access to the application.


Affected software

WAX610D
WAX650S
NWA110AX
WAX510D
NWA210AX
WAC500H
NWA90AX
NWA90AX PRO
WAX640S-6E
NWA90BE
WAX630S
NWA90BE PRO
WAX620D-6E
WAX655E
NWA110BE
NWA130BE
WAX300H
NWA240BE
NWA210AXv2
NWA220AX-6E
NWA210BE
NWA50BE
IAP500BE
NWA30BE
USG LITE 60AX
NWA50AX
FWA7 Root Plus
NWA50AX PRO
FWA7 Leaf Plus
WBE665S
WBE660S
NWA55AXE
WBE630S
NWA55AX PRO
WBE510D
NWA55AX PTP
WBE530
NWA55BE
NWA50BE PRO

How to mitigate CVE-2026-8508

Install updates from vendor's website.

WAX610D - update to 7.12(ABTE.0)C0
NWA90AX - update to 7.12(ACCV.0)C0
WAX650S - update to 7.12(ABRM.0)C0
NWA90AX PRO - update to 7.12(ACGF.0)C0
WAX640S-6E - update to 7.12(ACCM.0)C0
NWA90BE - update to 7.40(ACPD.1)C0
WAX630S - update to 7.12(ABZD.0)C0
NWA90BE PRO - update to 7.40(ACPE.1)C0
WAX620D-6E - update to 7.12(ACCN.0)C0
NWA110AX - update to 7.12(ABTG.0)C0
WAX655E - update to 7.12(ACDO.0)C0
NWA110BE - update to 7.40(ACLZ.1)C0
WAX510D - update to 7.12(ABTF.0)C0
NWA130BE - update to 7.40(ACIL.1)C0
WAX300H - update to 7.12(ACHF.0)C0
NWA210AX - update to 7.12(ABTD.0)C0
NWA240BE - update to 7.40(ACQG.1)C0
NWA210AXv2 - update to 7.40(ACSR.1)C0
NWA220AX-6E - update to 7.12(ACCO.0)C0
NWA210BE - update to 7.40(ACLY.1)C0
NWA50BE - update to 7.40(ACPB.1)C0
IAP500BE - update to 7.40(ACPJ.1)C0
NWA30BE - update to 7.40(ACPI.1)C0
USG LITE 60AX - update to 2.40(ACIP.0)C0
NWA50AX - update to 7.12(ABYW.0)C0
FWA7 Root Plus - update to 7.40(ACQL.1)C0
NWA50AX PRO - update to 7.12(ACGE.0)C0
FWA7 Leaf Plus - update to 7.40(ACQK.1)C0
WBE665S - update to 7.40(ACQJ.1)C0
WBE660S - update to 7.40(ACGG.1)C0
NWA55AXE - update to 7.12(ABZL.0)C0
WBE630S - update to 7.40(ACLW.1)C0
NWA55AX PRO - update to 7.12(ACSP.0)C0
WBE510D - update to 7.40(ACLX.1)C0
NWA55AX PTP - update to 7.12(ACSQ.0)C0
WBE530 - update to 7.40(ACLE.1)C0
NWA55BE - update to 7.40(ACPH.1)C0
NWA50BE PRO - update to 7.40(ACPC.1)C0

External References

Related Security Bulletins