Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-58457: Shenzhen Aitemi M300 Wi-Fi Repeater allows network access to execute commands
CVE-2026-58457
Summary
The Shenzhen Aitemi M300 Wi-Fi Repeater has a security flaw that lets hackers with access to the same network take control of the device. This is because the device doesn't check the input it receives from the internet, allowing malicious commands to be executed. To stay safe, consider replacing or updating the device with a more secure model.
Original title
Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows network-adjacent attackers to execute arbitrary shell commands b...
Original description
Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows network-adjacent attackers to execute arbitrary shell commands by injecting unsanitized input through the smacfilter_conf handler in the commuos web backend. Attackers can append semicolon-delimited payloads to the name, enable, or mac GET parameters, which are passed without sanitization into sprintf() to build uci shell commands executed via doSystemCmdComlib(), granting full root-level control of the device.
nvd CVSS3.1
9.8
nvd CVSS4.0
9.3
Vulnerability type
CWE-78
OS Command Injection
Published: 1 Jul 2026 · Updated: 22 Jul 2026 · First seen: 1 Jul 2026