CVE-2026-36828
Description
A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and including v7.7. The CGI component allows authenticated users to execute arbitrary shell commands with root privileges via the action=runcmd parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Authenticated command injection in Panabit PAP-XM320 /cgi-bin/tools/ajax_cmd allows root-level RCE.
Vulnerability
A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and including version v7.7 [1]. The CGI component insufficiently sanitizes user-supplied input when handling the action=runcmd parameter, allowing authenticated users to inject arbitrary operating system commands.
Exploitation
An attacker must first authenticate to the Panabit web interface. Once authenticated, they can send a crafted HTTP request to /cgi-bin/tools/ajax_cmd with action=runcmd and a malicious payload appended to the command parameter. No special network position is required beyond network access to the management interface, and no user interaction beyond the attacker's own browser session is needed.
Impact
Successful exploitation allows an authenticated attacker to execute arbitrary shell commands with root privileges on the affected device. This results in full compromise of the confidentiality, integrity, and availability of the system, including the ability to read or modify any file, install persistent backdoors, or disrupt network operations.
Mitigation
Panabit has not yet released a fixed version for PAP-XM320 at the time of publication [1]. Users should restrict network access to the management interface to trusted administrators only and monitor for unauthorized activity. The vendor page [1] should be consulted for future patch availability.
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.