Home

Description

An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session cookies using a filesystem existence check based on a user-controlled cookie value without proper sanitization, allowing directory traversal and bypass of authentication.

PUBLISHED Reserved 2026-04-06 | Published 2026-05-19 | Updated 2026-05-19 | Assigner mitre

References

secreu.notion.site/...36829-3652c0ab461580e19704e87b18865714 exploit

www.panabit.com/

secreu.notion.site/...36829-3652c0ab461580e19704e87b18865714

cve.org (CVE-2026-36829)

nvd.nist.gov (CVE-2026-36829)

Download JSON