CVE-2026-19910
Received Received - Intake

Signature Verification Bypass in PAX Technology Q80 Application Installer

Vulnerability report for CVE-2026-19910, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-14

Last updated on: 2026-08-14

Assigner: Zero Day Initiative

Description

PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The specific flaw exists within the application installer. The issue results from the lack of proper verification of a cryptographic signature before installing an application. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-30585.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-14
Last Modified
2026-08-14
Generated
2026-08-15
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pax_technology q80 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in PAX Technology Q80 allows network-adjacent attackers to execute arbitrary code without authentication. The flaw occurs because the application installer does not properly verify cryptographic signatures before installing software, enabling attackers to bypass security and gain root access.

Detection Guidance

Detecting this vulnerability requires checking for the presence of PAX Technology Q80 devices on your network and verifying if they are running vulnerable firmware. Inspect network traffic for unusual application installation requests or unauthorized code execution attempts. Monitor logs for signs of root-level access or unexpected application installations.

Impact Analysis

An attacker could exploit this to install malicious software, take control of the device, or access sensitive data. Since authentication is not required, any attacker within network range could potentially compromise the system, leading to unauthorized code execution and elevated privileges.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR and HIPAA requirements for data protection and security. Organizations using affected PAX Q80 devices may face compliance violations, legal penalties, and reputational damage due to insufficient security controls.

Mitigation Strategies

Immediately restrict network access to PAX Technology Q80 devices to prevent network-adjacent attackers from exploiting this flaw. Isolate affected devices from critical systems and avoid installing untrusted applications. Since no official patches are available, limiting interaction with the product is the only mitigation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19910. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart