CVE-2025-34152: Shenzhen Aitemi E Commerce Co. Ltd m300 Wi-Fi Repeater

Critical severity, CVSS 9.4. EPSS: 86.8% chance of exploitation in the next 30 days.

An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) via the 'time' parameter of the '/protocol.csp?' endpoint. The input is processed by the internal date '-s' command without rebooting or disrupting HTTP service. Unlike other injection points, this vector allows remote compromise without triggering visible configuration changes.

Affected products

Published 2025-08-07. Last modified 2026-06-17.