{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wax650s/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":6.5,"id":"CVE-2026-8508"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WAX650S","FWA7 Series","Security Router"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Zyxel"],"content_html":"\u003cp\u003eCVE-2026-8508 is a pre-authentication trust-boundary vulnerability affecting the social_login.cgi component in Zyxel network devices. The vulnerability was identified during research into the WAX650S access point (V7.10(ABRM.4)C0), where the backend improperly trusted user-supplied fields, specifically the 'fb_user' parameter, submitted during the social login flow. An unauthenticated attacker can craft a POST request to '/cgi-bin/social_login.cgi' to trigger the issuance of a guest authentication cookie without performing the legitimate Facebook-side identity validation.\u003c/p\u003e\n\u003cp\u003eZyxel released an advisory on August 4, 2026, confirming that the flaw impacts 39 models, including 36 access points, two FWA7 series devices, and one security router. The vulnerability enables an attacker with network adjacency to bypass captive portal restrictions, potentially granting unauthorized access to the network or services protected by the captive portal.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers with network adjacency to bypass captive portal authentication. This grants the attacker a valid guest authentication cookie, enabling unauthorized network access. The vulnerability affects 39 distinct Zyxel models, increasing the risk surface for enterprise and public-facing deployments utilizing Zyxel captive portal social login features.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrioritize patching all affected Zyxel devices as identified in the manufacturer's August 4, 2026, advisory.\u003c/li\u003e\n\u003cli\u003eMonitor logs for anomalous POST requests directed at '/cgi-bin/social_login.cgi' originating from the guest or public-facing network segments.\u003c/li\u003e\n\u003cli\u003eDeploy network-level access control to restrict access to management and CGI interfaces from untrusted or public network interfaces.\u003c/li\u003e\n\u003cli\u003eVerify firmware versions across the 36 affected access points, FWA7 series, and the impacted security router model.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-16T18:43:30Z","date_published":"2026-08-16T18:43:30Z","id":"https://feed.craftedsignal.io/briefs/2026-08-zyxel-captive-portal-bypass/","summary":"A pre-authentication trust-boundary flaw in Zyxel network devices, tracked as CVE-2026-8508, allows unauthenticated attackers to bypass captive portal authentication via crafted POST requests to the social_login.cgi endpoint.","title":"Pre-Authentication Trust Boundary Vulnerability in Zyxel Social Login","url":"https://feed.craftedsignal.io/briefs/2026-08-zyxel-captive-portal-bypass/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-6837"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=D8F7FACB-F5F9-558A-A08D-F0A42337381F\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["WAX650S firmware","WAX650S"],"_cs_severities":["high"],"_cs_tags":["cve","command-injection","zyxel","network-infrastructure"],"_cs_type":"advisory","_cs_vendors":["Zyxel"],"content_html":"\u003cp\u003eCVE-2026-6837 describes a post-authentication command injection vulnerability affecting the 'export-cgi' CGI program within Zyxel WAX650S access point firmware. The vulnerability exists in all firmware versions up to and including 7.10(ABRM.4)C0. An attacker who has already obtained legitimate administrative credentials for the web management interface can leverage this flaw to inject and execute arbitrary commands at the operating system level. Because this vulnerability requires existing administrative access, the primary risk involves privilege escalation or persistence for an attacker who has successfully performed initial credential compromise. Organizations utilizing these devices should prioritize upgrading to patched firmware versions and auditing active administrative sessions.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs credential theft or brute-force to obtain administrator-level access to the web management interface.\u003c/li\u003e\n\u003cli\u003eAttacker logs into the device management console via HTTP or HTTPS.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to or directly crafts a request to the 'export-cgi' endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker injects malicious OS command sequences into the request parameters processed by 'export-cgi'.\u003c/li\u003e\n\u003cli\u003eThe CGI program fails to neutralize shell metacharacters, passing the input directly to the system shell.\u003c/li\u003e\n\u003cli\u003eThe system executes the injected commands with the privileges of the web service process.\u003c/li\u003e\n\u003cli\u003eAttacker establishes persistent access or exfiltrates configuration data from the device.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full control of the affected Zyxel WAX650S access point. This can lead to total loss of device confidentiality, integrity, and availability, as well as the potential for the device to be used as a pivot point for further lateral movement within the network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the vendor-provided firmware update that addresses CVE-2026-6837 on all Zyxel WAX650S units immediately.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for anomalous POST or GET requests directed at 'export-cgi' by known administrative accounts.\u003c/li\u003e\n\u003cli\u003eLimit access to the device management interface to specific internal management VLANs or dedicated jump hosts to minimize the exposure of administrative endpoints.\u003c/li\u003e\n\u003cli\u003eMonitor for unexpected system processes or network connections originating from the WAX650S device.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-16T18:43:37Z","date_published":"2026-08-04T03:43:32Z","id":"https://feed.craftedsignal.io/briefs/2026-08-zyxel-export-cgi-rce/","summary":"An authenticated administrator can exploit a command injection vulnerability in the export-cgi program of Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 to execute arbitrary OS commands.","title":"Command Injection in Zyxel WAX650S export-cgi","url":"https://feed.craftedsignal.io/briefs/2026-08-zyxel-export-cgi-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - WAX650S","version":"https://jsonfeed.org/version/1.1"}