Product
medium
advisory
Pre-Authentication Trust Boundary Vulnerability in Zyxel Social Login
1 rule 1 TTP 1 CVEA pre-authentication trust-boundary flaw in Zyxel network devices, tracked as CVE-2026-8508, allows unauthenticated attackers to bypass captive portal authentication via crafted POST requests to the social_login.cgi endpoint.
WAX650S +2
1r
1t
1c
high
advisory
Command Injection in Zyxel WAX650S export-cgi
1 rule 1 TTP 1 CVEAn authenticated administrator can exploit a command injection vulnerability in the export-cgi program of Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 to execute arbitrary OS commands.
PoC
WAX650S firmware +1
cve
command-injection
zyxel
network-infrastructure
1r
1t
1c
updated