CVE Feed

    Dashboard / CVE / CVE-2026-58457

    CVE-2026-58457

    Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows network-adjacent attackers to execute arbitrary shell commands by injecting unsanitized input through the smacfilter_conf handler in the commuos web backend. Attackers can append semicolon-delimited payloads to the name, enable, or mac GET parameters, which are passed without sanitization into sprintf() to build uci shell commands executed via doSystemCmdComlib(), granting full root-level control of the device.

    Published:Jul 1, 2026
    Last Modified:Jul 29, 2026
    EPS:Jul 1, 2026
    EPSS Score:0.01657
    CVSS Score:9.8

    Affected Products

    Vendor
    Shenzhen Aitemi
    Product
    M300 Wifi Repeater

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High