VYPR

WAX650S

by Zyxel

CVEs (2)

  • CVE-2026-8508Aug 4, 2026
    risk 0.00cvss epss 0.01

    An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass captive portal authentication.

  • CVE-2026-6837Aug 4, 2026
    risk 0.00cvss epss 0.01

    A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.