Back to search
CVE-2025-34148
Published: Aug 7, 2025
Modified: Dec 1, 2025
PUBLISHED
Description
An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). When configuring the device in WISP mode, the 'ssid' parameter is passed unsanitized to system-level scripts. This allows remote attackers within Wi-Fi range to inject arbitrary shell commands that execute as root, resulting in full device compromise.
| Vendor | Product | Versions |
|---|---|---|
Shenzhen Aitemi E Commerce Co. Ltd. | M300 Wi-Fi Repeater | affected * |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now