Back

CRITICAL

Shenzhen Aitemi M300 Wi-Fi Repeater PPPoE Password Command Injection

Published Aug 7, 2025

Description

A command injection vulnerability exists in the 'passwd' parameter of the PPPoE setup process on the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). The input is passed directly to system-level commands without sanitation, enabling unauthenticated attackers to achieve root-level code execution.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 7, 2025
Updated Dec 1, 2025
Reserved Apr 15, 2025
CISA Vulnrichment
Updated Aug 7, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Aug 7, 2025
Updated Dec 1, 2025
Exploited since n/a
EUVD-2025-23926