Executive brief
A security vulnerability exists in the Panabit PAP-XM320 network gateway, a device used for traffic management and network auditing. An authorized user with access to the management interface can exploit a flaw in how the system processes commands to take full control of the device. This could allow an attacker to disrupt network operations, intercept traffic, or gain a foothold within the corporate network.
Technical details
A command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface invokes a backend helper utility located at /usr/sbin/pappiw and passes user-controlled parameters to it. The helper performs unsafe argument processing using the 'eval' function, which fails to properly sanitize input. An authenticated remote attacker with access to the management interface can inject malicious shell commands into these arguments. Successful exploitation results in arbitrary command execution with the privileges of the helper process, typically leading to full system compromise.
Affected products
- Panabit PAP-XM320 Up to and including V7.7
Timeline
- 2026-05-19: disclosed: Initial publication of CVE-2026-36827
- 2026-05-19: advisory