(0Day) PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability

August 5th, 2026

Vulnerability Details

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the application installer. The issue results from the lack of proper verification of a cryptographic signature before installing an application. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root.

Additional Details

04/22/26 - ZDI reported the vulnerability to the vendor
04/23/26 - the vendor confirmed that the reported firmware was end-of-life and no longer supported
04/28/26 - ZDI communicated that the users can’t update to a newer firmware
07/11/26 - ZDI disagreed with the vendor’s assessment and provided more evidence
07/13/26 - the vendor disputed the impact on supported releases
07/21/26 - the vendor confirmed the issue on the reported firmware
07/27/26 - the vendor requested an extension until April 2027
07/27/26 - ZDI notified the vendor of the intention to publish the case as a 0-day advisory

-- Mitigation: Given the nature of the vulnerability, the only salient mitigation strategy is to restrict interaction with the product


Disclosure Timeline

  • 2026-04-22 - Vulnerability reported to vendor
  • 2026-08-05 - Coordinated public release of advisory
  • 2026-08-05 - Advisory Updated

Credit

Steven Yu of TrendAI Research

Back to Advisories