<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Security Router - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/security-router/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 16 Aug 2026 18:43:30 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/security-router/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Pre-Authentication Trust Boundary Vulnerability in Zyxel Social Login</title><link>https://feed.craftedsignal.io/briefs/2026-08-zyxel-captive-portal-bypass/</link><pubDate>Sun, 16 Aug 2026 18:43:30 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-zyxel-captive-portal-bypass/</guid><description>A pre-authentication trust-boundary flaw in Zyxel network devices, tracked as CVE-2026-8508, allows unauthenticated attackers to bypass captive portal authentication via crafted POST requests to the social_login.cgi endpoint.</description><content:encoded><![CDATA[<p>CVE-2026-8508 is a pre-authentication trust-boundary vulnerability affecting the social_login.cgi component in Zyxel network devices. The vulnerability was identified during research into the WAX650S access point (V7.10(ABRM.4)C0), where the backend improperly trusted user-supplied fields, specifically the 'fb_user' parameter, submitted during the social login flow. An unauthenticated attacker can craft a POST request to '/cgi-bin/social_login.cgi' to trigger the issuance of a guest authentication cookie without performing the legitimate Facebook-side identity validation.</p>
<p>Zyxel released an advisory on August 4, 2026, confirming that the flaw impacts 39 models, including 36 access points, two FWA7 series devices, and one security router. The vulnerability enables an attacker with network adjacency to bypass captive portal restrictions, potentially granting unauthorized access to the network or services protected by the captive portal.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers with network adjacency to bypass captive portal authentication. This grants the attacker a valid guest authentication cookie, enabling unauthorized network access. The vulnerability affects 39 distinct Zyxel models, increasing the risk surface for enterprise and public-facing deployments utilizing Zyxel captive portal social login features.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Prioritize patching all affected Zyxel devices as identified in the manufacturer's August 4, 2026, advisory.</li>
<li>Monitor logs for anomalous POST requests directed at '/cgi-bin/social_login.cgi' originating from the guest or public-facing network segments.</li>
<li>Deploy network-level access control to restrict access to management and CGI interfaces from untrusted or public network interfaces.</li>
<li>Verify firmware versions across the 36 affected access points, FWA7 series, and the impacted security router model.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category></item></channel></rss>