CVE 9.4 CRITICAL

Shenzhen Aitemi M300 Wi-Fi Repeater PPPoE Username Command Injection_CVE-2025-34150

9.4 / 10
CRITICAL
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

The PPPoE configuration interface of the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) is vulnerable to command injection via the 'user' parameter. Input is processed unsafely during network setup, allowing attackers to execute arbitrary system commands with root privileges.

Basic Information

ID CVE-2025-34150
Source VulnCheck
Published Aug 7, 2025 at 16:45

Affected Product

Vendor Shenzhen Aitemi E Commerce Co. Ltd.
Product M300 Wi-Fi Repeater
Version *
Affected Versions Shenzhen Aitemi E Commerce Co. Ltd. M300 Wi-Fi Repeater *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.