Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the Shenzhen Aitemi M300 Wi-Fi Repeater, specifically in hardware model MT02. The issue arises in the '/protocol.csp?' endpoint, where the 'time' parameter is processed by the internal date '-s' command. This vulnerability allows unauthenticated remote code execution as root, without disrupting HTTP service or requiring a device reboot. Unlike other injection points, this method enables stealthy exploitation without visible configuration changes.

Impact

Exploitation of this vulnerability leads to unauthorized remote code execution with root privileges on the affected device.

Reproduction

The vulnerability can be reproduced by sending a POST request to the '/protocol.csp?' endpoint with the 'time' parameter injected with shell commands. The injected command is executed immediately, allowing for remote code execution without rebooting the device or disrupting HTTP service.

Added: Aug 7, 2025, 5:33 PM
Updated: Aug 7, 2025, 5:33 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
0.3
threat
6.9
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.