CVE-2026-19348: Shenzhen Aitemi M300 Wi-Fi Repeater protocol.csp sprintf command injection
A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilterconf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19348?
CVE-2026-19348 has a critical severity score of 9.8.
How do I fix CVE-2026-19348?
To fix CVE-2026-19348, update the Shenzhen Aitemi M300 Wi-Fi Repeater firmware to the latest version that addresses this security vulnerability.
What impact does CVE-2026-19348 have?
CVE-2026-19348 allows for command injection through the manipulation of specific arguments in the device's firmware.
Is CVE-2026-19348 a remote vulnerability?
Yes, CVE-2026-19348 is classified as a remote vulnerability, allowing attackers to exploit it from an untrusted network.
Which devices are affected by CVE-2026-19348?
CVE-2026-19348 specifically affects the Shenzhen Aitemi M300 Wi-Fi Repeater model r0-ea7890a.