CVE-2026-19348

Summary

A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.

Affected Software

VendorProductVersion RangeStatus
Shenzhen AitemiM300 Wi-Fi Repeaterr0-ea7890aaffected

Weaknesses

  • CWE-77: Command Injection
  • CWE-74: Injection

References