CVE-2025-34151: Shenzhen Aitemi E Commerce Co. Ltd m300 Wi-Fi Repeater
Critical severity, CVSS 9.4. EPSS: 3.7% chance of exploitation in the next 30 days.
A command injection vulnerability exists in the 'passwd' parameter of the PPPoE setup process on the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). The input is passed directly to system-level commands without sanitation, enabling unauthenticated attackers to achieve root-level code execution.
Affected products
- Shenzhen Aitemi E Commerce Co. Ltd m300 Wi-Fi Repeater: any version
Published 2025-08-07. Last modified 2026-06-17.