
CVE-2026-36828 A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and including v7.7. The CGI component allows authenticated… https://www.cve.org/CVERecord?id=CVE-2026-36828
Post summary
The text announces a command‑injection vulnerability in Panabit PAP‑XM320's ajax_cmd endpoint, limited to versions up to 7.7, without mentioning PoCs, exploits, or patches.
