216.73.217.22

CVE-2025-34149

· Published 07/08/2025 17:15 · Modified 07/08/2025 21:26

Labels: CVE-2025-34149 2025-08-07CVE-2025-34149CWE-78[email protected]

Essential information

Published
07/08/2025 17:15
Modified
07/08/2025 21:26
Author
Creator
CVSS
9.4 CRITICAL (v3) 9.4 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A command injection vulnerability affects the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) during WPA2 configuration. The 'key' parameter is interpreted directly by the system shell, enabling attackers to execute arbitrary commands as root. Exploitation requires no authentication and can be triggered during wireless setup.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
shenzhen / aitemi m300 wifi repeater cpe:2.3:h:shenzhen:aitemi_m300_wifi_repeater:mt02:*:*:*:*:*:*:*

References