{"id":"CVE-2026-19348","title":"A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a","summary":"A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipul…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-74","CWE-77"],"published":"2026-08-09","updated":"2026-08-09","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19348","references":[{"url":"https://github.com/IEATASICS/m300-repeater-bugs","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-19348","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/865682","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/865683","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/865684","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/387184","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/387184/cti","label":"cna@vuldb.com"}],"tags":["nvd"],"ingestedAt":"2026-08-09T18:34:00.905Z","epss":0.01973,"epssPercentile":0.79315,"slug":"CVE-2026-19348","body":"## Overview\n\nA security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}