A vulnerability classified as very critical was found in Zyxel WAX650S up to 7.10(ABRM.4)C0. Impacted is an unknown function of the file social_login.cgi of the component Captive Portal. Such manipulation leads to improper authentication.
This vulnerability is uniquely identified as CVE-2026-8508. The attack can be launched remotely. No exploit exists.