CVE-2026-36828
8.8Panabit · PAP-XM320
A command injection vulnerability in the Panabit PAP-XM320 /cgi-bin/tools/ajax_cmd endpoint allows authenticated attackers to execute arbitrary system commands.
Executive summary
A critical command injection vulnerability in Panabit PAP-XM320 allows authenticated attackers to achieve total system compromise.
Vulnerability
The vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint, which fails to properly validate input, allowing an authenticated user to execute arbitrary shell commands on the underlying operating system.
Business impact
The ability to execute arbitrary commands on a network device like the PAP-XM320 poses a severe risk, as it allows for full control of the device, potential lateral movement into the internal network, and interception of traffic. With a CVSS score of 8.8, this vulnerability is highly dangerous; unauthorized access to administrative functions could lead to a total loss of confidentiality, integrity, and availability of the affected system.
Remediation
Immediate Action: Monitor vendor communication channels for security updates and apply them immediately upon release to remediate the command injection flaw.
Proactive Monitoring: Audit device access logs for unusual administrative activity and monitor for unauthorized command execution patterns or unexpected system process creation.
Compensating Controls: Restrict access to the device management interface to only trusted administrative IP addresses via firewall rules to reduce the likelihood of unauthorized exploitation.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the existence of a proof-of-concept and the high CVSS severity, this vulnerability should be treated with extreme urgency. Administrators must restrict access to the management interface and apply vendor patches the moment they become available.