CVE-2026-8508 is an improper-authentication vulnerability in the Zyxel WAX650S captive-portal social-login CGI component in firmware through 7.10(ABRM.4)C0. The social-login flow improperly trusts browser-submitted Facebook identity fields, permitting an attacker to cross the authentication trust boundary without completing captive-portal authentication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a real exploit PoC plus a substantial local emulation/rehosting toolkit for analyzing CVE-2026-8508, a Zyxel captive-portal social-login trust-boundary flaw. The core exploit is simple: poc/verify_social_login.sh sends an unauthenticated POST to /cgi-bin/social_login.cgi with attacker-controlled fb_user and related fb_* fields, then checks for Set-Cookie: authtok= as proof of guest-session issuance. The included decompiled CGI (decomp/social_login_20260501.c) supports the claim: on POST, it parses fb_user, fb_locale, fb_age, and fb_gender, generates a token, enters local UAM social-login helpers, and reaches cookie issuance without visible server-side verification of a Facebook token, OAuth state, nonce, or similar proof object. This makes the main capability a pre-auth captive-portal bypass leading to unauthorized guest admission rather than code execution. Repository structure is split into: (1) public documentation and writeup (README.md, writeup.md, index.html); (2) evidence and reverse-engineering notes under evidence/; (3) decompiled target CGI under decomp/; (4) a narrow PoC under poc/; and (5) a large emulation/ directory containing Bash and Python tooling to unpack firmware, prepare a runnable rootfs, seed Zyxel IPC objects, emulate AF_UNIX UAM and wireless HAL services, repair portal runtime state, and exercise the portal flow under qemu-aarch64 + bubblewrap. The emulation scripts are not the exploit themselves; they recreate enough of the Zyxel runtime to validate the vulnerable path and observe authtok issuance locally. Notable network and target surfaces include the vulnerable CGI /cgi-bin/social_login.cgi, related portal endpoints /userdata.html and /cgi-bin/Clicktocontinue.cgi, the Zyxel captive-portal hostname nap-slogin.nebula.zyxel.com, and the client-side Facebook Graph API call https://graph.facebook.com/me?fields=name,email&access_token=... described in the evidence. Local IPC endpoints used by the lab include AF_UNIX sockets such as runroot/dev/user-request, runroot/dev/user-notify, and runroot/tmp/wirelesshaldebug, plus several SysV IPC keys. Overall maturity is OPERATIONAL: the PoC is functional and directly demonstrates the bypass, while the surrounding tooling provides a reproducible research/emulation environment rather than a weaponized framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A trust-boundary bypass vulnerability in Zyxel social_login.cgi affecting the captive-portal social-login flow, allowing a pre-auth captive-portal bypass via browser-submitted Facebook identity fields.
An improper authentication vulnerability in the social_login.cgi CGI program of certain Zyxel APs, FWA7 devices, and Security Routers that could allow a WLAN attacker to bypass captive portal authentication.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.