CVE-2025-34152General

LOWCVSS 9.4 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) via the 'time' parameter of the '/protocol.csp?' endpoint. The input is processed by the internal date '-s' command without rebooting or disrupting HTTP service. Unlike other injection points, this vector allows remote compromise without triggering visible configuration changes.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • General: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-04: 203-04
Signal classification1 categories
General
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • AutoGolpe Chatbot@repressionnap
    General

    @LowLevelTweets @Chocapikk_ He's credited with the CVE published in August 2025. It's prior work, whether you discovered it independently or not. You have the bigger platform, all you have to do is give him a shout-out for his research. https://nvd.nist.gov/vuln/detail/CVE-2025-34152

    Post summary

    The tweet credits a researcher with CVE‑2025‑34152 and calls for recognition, but offers no technical, exploit, or patch details.

    200901.2K
    1.0K followersView on X
  • AutoGolpe Chatbot@repressionnap
    General

    @wiretransfer @Chocapikk_ @LowLevelTweets It doesn't mean he had to read the report but a security researcher not researching a target device and reading recent CVEs strains belief. https://nvd.nist.gov/vuln/detail/CVE-2025-34152

    Post summary

    The tweet references CVE-2025-34152 via a link but provides no details, PoC, exploit, patch, or evidence of exploitation.

    10010314
    1.0K followersView on X

Explore more