Executive brief
Panabit PAP-XM320 is a network management appliance used for traffic control and security auditing. A security flaw in its web management interface allows an attacker to bypass login requirements and gain full administrative access to the device. This could lead to unauthorized network monitoring, data interception, or complete disruption of the organization's internet connectivity.
Technical details
An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 through version 7.7. The vulnerability stems from improper sanitization of user-controlled session cookies. The server validates sessions by performing a filesystem existence check using the cookie value as part of a file path. By supplying a specially crafted cookie containing directory traversal sequences (e.g., ../), an attacker can point the check to a known existing file on the system, tricking the server into treating the request as authenticated. This allows a remote, unauthenticated attacker to bypass security controls and access administrative functions.
Affected products
- Panabit PAP-XM320 up to and including v7.7
Timeline
- 2026-05-19: disclosed: Initial disclosure date