CyberRota
Back to database

CVE-2026-36827

MEDIUM · CVSS 5.4 EPSS 0.74%

Source: NVD + CISA KEV + EPSS · Published: 2026-05-19 · Last synced: 2026-06-17

CyberRota Analysis

Uzaktan istismar edilebilir olabilir.

CVE
CVE-2026-36827
Severity
MEDIUM
CVSS
5.4
EPSS
0.74%

Original NVD Description

A command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface invokes the backend helper /usr/sbin/pappiw and passes user-controlled parameters to it. The helper performs unsafe argument processing using eval, which allows command injection when attacker-controlled input is included in the arguments. As a result, an authenticated remote attacker with access to the management interface may execute arbitrary shell commands.