Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.9

CVE-2026-19348: Shenzhen Aitemi M300 Wi-Fi Repeater allows remote command execution

CVE-2026-19348 · published 26 days ago
Summary

A security flaw in the Shenzhen Aitemi M300 Wi-Fi Repeater allows hackers to remotely take control of the device. This could happen if an attacker sends the device a malicious message. We recommend that you update the device to the latest version to fix this issue.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
shenzhen aitemi m300 wi-fi repeater r0-ea7890a
Original advisory text
Shenzhen Aitemi M300 Wi-Fi Repeater protocol.csp sprintf command injection
A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
References
Severity
8.9 High
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS 2%
Type
CWE-77Command Injection
CWE-74Injection
Timeline
Published9 Aug 2026
Updated30 Aug 2026
First seen9 Aug 2026
Sources
CVE-2026-19348 · MITRE
Monitor software like this
Free during beta