CVE-2026-36827
MEDIUMPanabit PAP-XM320 <= V7.7 - Authenticated Command Injection via /usr/sbin/pappiw Helper
Title source: llmDescription
A command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface invokes the backend helper /usr/sbin/pappiw and passes user-controlled parameters to it. The helper performs unsafe argument processing using eval, which allows command injection when attacker-controlled input is included in the arguments. As a result, an authenticated remote attacker with access to the management interface may execute arbitrary shell commands.
References (2)
Core 2
Scores
CVSS v3
5.4
EPSS
0.0074
EPSS Percentile
49.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-78
Status
published
Published
May 19, 2026
Tracked Since
May 19, 2026