CVE-2026-19348
Received Received - Intake

Command Injection in Shenzhen Aitemi M300 Wi-Fi Repeater

Vulnerability report for CVE-2026-19348, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-09

Last updated on: 2026-08-09

Assigner: VulDB

Description

A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-09
Last Modified
2026-08-09
Generated
2026-08-09
AI Q&A
2026-08-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
shenzhen aitemi_m300_wifi_repeater *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a command injection flaw in the Shenzhen Aitemi M300 Wi-Fi Repeater. It exists in the sprintf function of the file /protocol.csp when handling parameters like enable, name, and mac in the smacfilter_conf function. Attackers can manipulate these parameters via crafted HTTP requests to execute arbitrary shell commands on the device remotely.

Detection Guidance

To detect this vulnerability, scan your network for devices running the Shenzhen Aitemi M300 Wi-Fi Repeater firmware. Check for unauthenticated HTTP requests to the /protocol.csp endpoint with parameters like name, enable, or mac. Look for abnormal command execution attempts or unexpected file creation on the device.

Impact Analysis

This vulnerability allows remote attackers to execute arbitrary commands on the device with the privileges of the webserver, which runs as root. This could lead to full system compromise, including unauthorized file creation, password changes, or other malicious activities. The exploit is publicly available, increasing the risk of attacks.

Compliance Impact

This vulnerability could lead to unauthorized access and control of network devices, potentially exposing sensitive data. This may violate compliance requirements under GDPR (data protection) and HIPAA (health information security) due to inadequate security controls and potential data breaches.

Mitigation Strategies

Immediately disconnect the device from your network. Disable remote access to the web interface. Update the firmware if a patch is available. Monitor network traffic for suspicious activity targeting the /protocol.csp endpoint. Consider replacing the device if no fix is provided.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19348. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart