{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/m300-wi-fi-repeater-r0-ea7890a/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-19348"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["M300 Wi-Fi Repeater (r0-ea7890a)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Shenzhen Aitemi"],"content_html":"\u003cp\u003eA critical command injection vulnerability (CVE-2026-19348) has been identified in the Shenzhen Aitemi M300 Wi-Fi Repeater, specifically affecting firmware version r0-ea7890a. The vulnerability originates from the unsafe use of the 'sprintf' function within the '/protocol.csp' handler. An unauthenticated, remote attacker can manipulate the 'enable', 'name', or 'mac' parameters to inject and execute arbitrary commands on the underlying operating system. Because public exploit code is available, this vulnerability poses a significant risk to organizations using these devices in their network infrastructure. Defenders should restrict access to the management interface of affected devices and monitor for suspicious HTTP traffic directed at the '/protocol.csp' URI.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote code execution with the privileges of the web service. This could result in full device compromise, persistence, or use of the device as a pivot point for further lateral movement within the local network. Given that this is a Wi-Fi repeater, compromise provides an attacker with a strategic vantage point to intercept or manipulate local wireless traffic.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and inventory all Shenzhen Aitemi M300 Wi-Fi Repeaters on the network.\u003c/li\u003e\n\u003cli\u003eImplement network-level access controls (ACLs) to restrict access to the management interface of the M300 devices to trusted administrative IP addresses only.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for HTTP POST or GET requests to '/protocol.csp' containing shell metacharacters (e.g., ;, |, \u0026amp;, $, `) in the 'enable', 'name', or 'mac' parameters.\u003c/li\u003e\n\u003cli\u003eContact the vendor, Shenzhen Aitemi, for firmware updates that address the unsafe usage of 'sprintf' in the protocol handler.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-09T11:45:05Z","date_published":"2026-08-09T11:45:05Z","id":"https://feed.craftedsignal.io/briefs/2026-08-m300-repeater-rce/","summary":"The Shenzhen Aitemi M300 Wi-Fi Repeater is vulnerable to unauthenticated remote command injection via the /protocol.csp endpoint, allowing arbitrary system execution through parameter manipulation.","title":"Remote Command Injection in Shenzhen Aitemi M300 Wi-Fi Repeater","url":"https://feed.craftedsignal.io/briefs/2026-08-m300-repeater-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - M300 Wi-Fi Repeater (R0-Ea7890a)","version":"https://jsonfeed.org/version/1.1"}