Shenzhen Aitemi · M300 Wi-Fi Repeater · CVE-2026-58457
**Name of the Vulnerable Software and Affected Versions**
Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) (affected versions not specified)
**Description**
An unauthenticated OS command injection exists in the commuos web backend. Network-adjacent attackers can execute arbitrary shell commands by injecting unsanitized input through the `smacfilter conf` handler. By appending semicolon-delimited payloads to the `name`, `enable`, or `mac` GET parameters, attackers can manipulate the `sprintf()` function used to build uci shell commands executed via `doSystemCmdComlib()`, resulting in full root-level control of the device.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.