Executive brief
The Shenzhen Aitemi M300 (MT02) is a Wi-Fi repeater used to extend wireless network coverage. A security flaw in its web management interface allows an unauthorized person on the same network to take complete control of the device. By sending a specially crafted web request, an attacker can execute administrative commands, potentially leading to data interception or the use of the device as a foothold for further attacks on the local network.
Technical details
An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). The vulnerability is located within the 'smacfilter_conf' handler of the 'commuos' web backend. The application uses 'sprintf()' to construct 'uci' shell commands using unsanitized input from the 'name', 'enable', and 'mac' GET parameters. An attacker can inject semicolon-delimited shell commands into these parameters via the '/protocol.csp' endpoint. These commands are subsequently executed with root privileges via the 'doSystemCmdComlib()' function. As of the advisory date, no official patch has been confirmed.
Affected products
- Shenzhen Aitemi E Commerce Co. Ltd. M300 Wi-Fi Repeater (MT02) All versions
Timeline
- 2026-07-01: advisory
- 2026-07-01: disclosed