VYPR
Vendor

Shenzhen Aitemi

Products
3
CVEs
8
Across products
11
Status
Private

Products

3

Recent CVEs

8
  • CVE-2025-34152CriAug 7, 2025
    risk 0.69cvss epss 0.68

    An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) via the 'time' parameter of the '/protocol.csp?' endpoint. The input is processed by the internal date '-s' command without rebooting or disrupting HTTP…

  • CVE-2026-19348CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.02

    A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac…

  • CVE-2025-34151CriAug 7, 2025
    risk 0.61cvss epss 0.04

    A command injection vulnerability exists in the 'passwd' parameter of the PPPoE setup process on the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). The input is passed directly to system-level commands without sanitation, enabling unauthenticated attackers to achieve…

  • CVE-2025-34150CriAug 7, 2025
    risk 0.61cvss epss 0.01

    The PPPoE configuration interface of the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) is vulnerable to command injection via the 'user' parameter. Input is processed unsafely during network setup, allowing attackers to execute arbitrary system commands with root…

  • CVE-2025-34149CriAug 7, 2025
    risk 0.61cvss epss 0.01

    A command injection vulnerability affects the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) during WPA2 configuration. The 'key' parameter is interpreted directly by the system shell, enabling attackers to execute arbitrary commands as root. Exploitation requires no…

  • CVE-2025-34148CriAug 7, 2025
    risk 0.61cvss epss 0.01

    An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). When configuring the device in WISP mode, the 'ssid' parameter is passed unsanitized to system-level scripts. This allows remote attackers within Wi-Fi…

  • CVE-2025-34147CriAug 4, 2025
    risk 0.61cvss epss 0.01

    An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). When configuring the device in Extender mode via its captive portal, the extap2g SSID field is inserted unescaped into a reboot-time shell script. This…

  • CVE-2026-58457CriJul 1, 2026
    risk 0.00cvss 9.8epss 0.03

    Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows network-adjacent attackers to execute arbitrary shell commands by injecting unsanitized input through the smacfilter_conf handler in the commuos…