Vendor
critical
advisory
Remote Command Injection in Shenzhen Aitemi M300 Wi-Fi Repeater
1 rule 2 TTPs 1 CVEThe Shenzhen Aitemi M300 Wi-Fi Repeater is vulnerable to unauthenticated remote command injection via the /protocol.csp endpoint, allowing arbitrary system execution through parameter manipulation.
M300 Wi-Fi Repeater
1r
2t
1c
critical
advisory
CVE-2026-58457: Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated OS Command Injection
1 rule 2 TTPs 4 IOCsAn unauthenticated OS command injection vulnerability, CVE-2026-58457, exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02), allowing network-adjacent attackers to execute arbitrary shell commands and gain full root-level control by injecting unsanitized input into the `smacfilter_conf` handler's GET parameters within the `commuos` web backend.
M300 Wi-Fi Repeater +2
network
command-injection
vulnerability
firmware
iot
1r
2t
4i
updated