VYPR

WAX650S

by Zyxel

CVEs (2)

  • CVE-2026-6837HigAug 4, 2026
    risk 0.47cvss 7.2epss 0.01

    A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

  • CVE-2026-8508MedAug 4, 2026
    risk 0.00cvss 6.5epss 0.01

    An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication.