216.73.217.22

CVE-2025-34151

· Published 07/08/2025 17:15 · Modified 07/08/2025 21:26

Labels: CVE-2025-34151 2025-08-07CVE-2025-34151CWE-78[email protected]

Essential information

Published
07/08/2025 17:15
Modified
07/08/2025 21:26
Author
Creator
CVSS
9.4 CRITICAL (v3) 9.4 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A command injection vulnerability exists in the 'passwd' parameter of the PPPoE setup process on the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). The input is passed directly to system-level commands without sanitation, enabling unauthenticated attackers to achieve root-level code execution.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
shenzhen / aitemi m300 wifi repeater cpe:2.3:a:shenzhen:aitemi_m300_wifi_repeater:*:*:*:*:*:*:*:*

References