VYPR
High severity8.8NVD Advisory· Published May 19, 2026· Updated May 19, 2026

CVE-2026-36828

CVE-2026-36828

Description

A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and including v7.7. The CGI component allows authenticated users to execute arbitrary shell commands with root privileges via the action=runcmd parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated command injection in Panabit PAP-XM320 /cgi-bin/tools/ajax_cmd allows root-level RCE.

Vulnerability

A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and including version v7.7 [1]. The CGI component insufficiently sanitizes user-supplied input when handling the action=runcmd parameter, allowing authenticated users to inject arbitrary operating system commands.

Exploitation

An attacker must first authenticate to the Panabit web interface. Once authenticated, they can send a crafted HTTP request to /cgi-bin/tools/ajax_cmd with action=runcmd and a malicious payload appended to the command parameter. No special network position is required beyond network access to the management interface, and no user interaction beyond the attacker's own browser session is needed.

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary shell commands with root privileges on the affected device. This results in full compromise of the confidentiality, integrity, and availability of the system, including the ability to read or modify any file, install persistent backdoors, or disrupt network operations.

Mitigation

Panabit has not yet released a fixed version for PAP-XM320 at the time of publication [1]. Users should restrict network access to the management interface to trusted administrators only and monitor for unauthorized activity. The vendor page [1] should be consulted for future patch availability.

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.