Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Command Injection in Panabit PAP‑XM320 /cgi-bin/tools/ajax_cmd Endpoint Enables Root Shell Access |
Wed, 17 Jun 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Root Privilege Command Injection in Panabit PAP‑XM320 CGI Endpoint |
Tue, 16 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Root Privilege Command Injection in Panabit PAP‑XM320 CGI Endpoint |
Wed, 20 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Panabit
Panabit pap-xm320 |
|
| Vendors & Products |
Panabit
Panabit pap-xm320 |
Tue, 19 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Command Injection in Panabit PAP‑XM320 /cgi-bin/tools/ajax_cmd Enables Root Command Execution |
Tue, 19 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 19 May 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Command Injection in Panabit PAP‑XM320 /cgi-bin/tools/ajax_cmd Enables Root Command Execution | |
| Weaknesses | CWE-78 |
Tue, 19 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and including v7.7. The CGI component allows authenticated users to execute arbitrary shell commands with root privileges via the action=runcmd parameter. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-19T17:48:13.147Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-36828
Updated: 2026-05-19T17:46:59.635Z
Status : Deferred
Published: 2026-05-19T17:16:22.080
Modified: 2026-06-17T10:41:21.690
Link: CVE-2026-36828
No data.
OpenCVE Enrichment
Updated: 2026-06-18T14:30:15Z