CVE-2026-19348: Shenzhen Aitemi m300 Wi-Fi Repeater
Critical severity, CVSS 9.8. EPSS: 3.6% chance of exploitation in the next 30 days.
A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected products
- Shenzhen Aitemi m300 Wi-Fi Repeater: version r0-ea7890a only
Published 2026-08-09. Last modified 2026-08-12.