Impact
The Shenzhen Aitemi M300 Wi‑Fi repeater model MT02 contains an unauthenticated OS command injection flaw. Unsanitized user input entered through the smacfilter_conf handler is concatenated into a shell command via sprintf() and executed as root privileges through doSystemCmdComlib(). This allows an attacker to run arbitrary shell commands, giving full control of the device and potentially enabling configuration tampering, traffic interception, or lateral movement to other network devices. The weakness is identified as CWE‑78.
Affected Systems
The affected device is the Shenzhen Aitemi M300 Wi‑Fi repeater model MT02, manufactured by Shenzhen Aitemi E Commerce Co. Ltd. No specific firmware version is documented, implying that all releases before an update may be vulnerable. The flaw resides in the commuos web backend handling the smacfilter_conf endpoint.
Risk and Exploitability
The CVSS score is 9.3, reflecting a critical severity that compromises device integrity and confidentiality. The EPSS score of 2 % indicates a modest but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA KEV, meaning no widespread exploitation has been observed yet. Based on the description, it is inferred that attackers would most likely reach the device from adjacent local networks, as authentication is not required and the vulnerable endpoint is exposed via HTTP. Because the flaw grants root‑level control, any successful exploitation would fully compromise the device and could serve as a foothold for broader network attacks.
OpenCVE Enrichment