CVE-2026-58457

CRITICAL

Shenzhen Aitemi M300 MT02 Unauthenticated OS Command Injection via protocol.csp

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-58457. PoCs published by J4ck3LSyN-Gen2.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-58457, an unauthenticated OS command injection vulnerability in Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). The exploit targets unsanitized GET parameters in the `smacfilter_conf` handler, allowing remote root command execution via crafted HTTP requests.

Description

Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows network-adjacent attackers to execute arbitrary shell commands by injecting unsanitized input through the smacfilter_conf handler in the commuos web backend. Attackers can append semicolon-delimited payloads to the name, enable, or mac GET parameters, which are passed without sanitization into sprintf() to build uci shell commands executed via doSystemCmdComlib(), granting full root-level control of the device.

Exploits (1)

github WORKING POC
by J4ck3LSyN-Gen2 · pythonpoc
https://github.com/J4ck3LSyN-Gen2/CVE-2026-58457

This repository contains a functional exploit for CVE-2026-58457, an unauthenticated OS command injection vulnerability in Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). The exploit targets unsanitized GET parameters in the `smacfilter_conf` handler, allowing remote root command execution via crafted HTTP requests.

Classification
Working Poc 99%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02), firmware versions vulnerable to CVE-2026-58457
No auth needed
Prerequisites: Network access to the device's HTTP/HTTPS interface (typically port 80) · Vulnerable firmware version (pre-patch)
mistral-large-3 · analyzed Jul 17, 2026 Full analysis →

References (3)

Core 3

Scores

CVSS v3 9.8
EPSS 0.0166
EPSS Percentile 74.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
Shenzhen Aitemi E Commerce Co. Ltd./M300 Wi-Fi Repeater
Published Jul 01, 2026
Tracked Since Jul 02, 2026