(0Day) PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability

August 5th, 2026

Vulnerability Details

This vulnerability allows network-adjacent attackers to disclose sensitive information and modify configuration on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the XCB daemon. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root.

Additional Details

04/22/26 - ZDI reported the vulnerability to the vendor
04/23/26 - the vendor confirmed that the reported firmware was end-of-life and no longer supported
04/28/26 - ZDI communicated that the users can’t update to a newer firmware
07/11/26 - ZDI disagreed with the vendor’s assessment and provided more evidence
07/13/26 - the vendor disputed the impact on supported releases
07/21/26 - the vendor confirmed the issue on the reported firmware
07/27/26 - the vendor requested an extension until April 2027
07/27/26 - ZDI notified the vendor of the intention to publish the case as a 0-day advisory

-- Mitigation: Given the nature of the vulnerability, the only salient mitigation strategy is to restrict interaction with the product


Disclosure Timeline

  • 2026-04-22 - Vulnerability reported to vendor
  • 2026-08-05 - Coordinated public release of advisory
  • 2026-08-05 - Advisory Updated

Credit

Steven Yu of TrendAI Research

Back to Advisories