Product
A pre-authentication trust-boundary flaw in Zyxel network devices, tracked as CVE-2026-8508, allows unauthenticated attackers to bypass captive portal authentication via crafted POST requests to the social_login.cgi endpoint.