VYPR

MT02

by Shenzhen Aitemi

CVEs (3)

  • CVE-2025-34152CriAug 7, 2025
    risk 0.69cvss epss 0.61

    An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) via the 'time' parameter of the '/protocol.csp?' endpoint. The input is processed by the internal date '-s' command without rebooting or disrupting HTTP…

  • CVE-2025-34149CriAug 7, 2025
    risk 0.61cvss epss 0.01

    A command injection vulnerability affects the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) during WPA2 configuration. The 'key' parameter is interpreted directly by the system shell, enabling attackers to execute arbitrary commands as root. Exploitation requires no…

  • CVE-2025-34148CriAug 7, 2025
    risk 0.61cvss epss 0.01

    An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). When configuring the device in WISP mode, the 'ssid' parameter is passed unsanitized to system-level scripts. This allows remote attackers within Wi-Fi…