(0Day) PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability
Vulnerability Details
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the parsing of AIP files. By creating a symbolic link, an attacker can abuse the installer process to write arbitrary files. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root.
Additional Details
04/22/26 - ZDI reported the vulnerability to the vendor
04/23/26 - the vendor confirmed that the reported firmware was end-of-life and no longer supported
04/28/26 - ZDI communicated that the users can’t update to a newer firmware
07/11/26 - ZDI disagreed with the vendor’s assessment and provided more evidence
07/13/26 - the vendor disputed the impact on supported releases
07/21/26 - the vendor confirmed the issue on the reported firmware
07/27/26 - the vendor requested an extension until April 2027
07/27/26 - ZDI notified the vendor of the intention to publish the case as a 0-day advisory
-- Mitigation: Given the nature of the vulnerability, the only salient mitigation strategy is to restrict interaction with the product
Disclosure Timeline
- 2026-04-22 - Vulnerability reported to vendor
- 2026-08-05 - Coordinated public release of advisory
- 2026-08-05 - Advisory Updated
Credit
Steven Yu of TrendAI Research