Junglewise Threat Intelligence

CVE-2026-36828: Panabit PAP-XM320 command injection in ajax_cmd endpoint

CVE-2026-36828 · Severity: info · CVSS 8.8 · Published 2026-05-19

Technologies: Panabit PAP-XM320. Vendors: Panabit.

Executive brief

A security vulnerability exists in Panabit PAP-XM320 network gateways, which are used for traffic management and network auditing. An authorized user can exploit this flaw to take full control of the device by executing unauthorized system commands. This could allow an attacker to intercept network traffic, disrupt internet connectivity, or gain a foothold within the corporate network.

Technical details

A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 devices running firmware up to and including v7.7. The issue resides in the CGI component's handling of the 'action=runcmd' parameter, which fails to properly sanitize user input before passing it to a system shell. An authenticated attacker can exploit this to execute arbitrary commands with root-level privileges. While authentication is required, the ability to gain full OS-level access on a core networking appliance poses a significant risk to the integrity and confidentiality of the managed network.

Affected products

  • Panabit PAP-XM320 up to and including v7.7

Timeline

  • 2026-05-19: disclosed: CVE published to NVD dataset

References

Related threats