ZeroHour

CVE-2025-34152

Unauthenticated OS Command Injection in Shenzhen Aitemi M300 Wi-Fi Repeater

CVSS 4.0
9.4 critical
EPSS
69%p99
Published
()
Modified
AI analysis

CVE-2025-34152 is a critical (CVSS 4.0 score 9.4), unauthenticated OS command injection flaw (CWE-78) in the Shenzhen Aitemi M300 Wi-Fi Repeater, hardware model MT02. An attacker sends a crafted value in the 'time' parameter of the device's '/protocol.csp?' endpoint, which the firmware passes to the internal 'date -s' command, enabling arbitrary OS command execution without credentials; the CVSS 4.0 attack vector (AV:A) places the attacker on the adjacent network with reachability to the device's web interface. Notably, this injection executes without rebooting the repeater or disrupting its HTTP service, and unlike other injection points on the device it triggers no visible configuration changes, so a compromise can go undetected. Any deployment of this repeater model is affected; the disclosure data provides no affected or fixed firmware version ranges. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but EPSS assigns a 69.1% probability of exploitation within 30 days (99th percentile), signaling elevated near-term risk.

What to do: No patched firmware version is identified in the available data, so check with Shenzhen Aitemi or your point of purchase for an updated firmware image and apply it as soon as one is released; if none is available, consider replacing or isolating the repeater. In the interim, restrict web-management access to trusted clients on the local network segment and monitor for (or block) requests to '/protocol.csp?' whose 'time' parameter contains shell metacharacters. Given the high EPSS score, treat unpatched units as likely near-term targets.

Affected
Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) via the 'time' parameter of the '/protocol.csp?' endpoint. The input is processed by the internal date '-s' command without rebooting or disrupting HTTP service. Unlike other injection points, this vector allows remote compromise without triggering visible configuration changes.

Weakness
CWE-78
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news