CVE-2026-58457Disclosure

MEDIUMCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows network-adjacent attackers to execute arbitrary shell commands by injecting unsanitized input through the smacfilter_conf handler in the commuos web backend. Attackers can append semicolon-delimited payloads to the name, enable, or mac GET parameters, which are passed without sanitization into sprintf() to build uci shell commands executed via doSystemCmdComlib(), granting full root-level control of the device.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-07-16)
  • 7 total mentions across 4 days

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-07-01: 2Mentions · 2026-07-02: 1Mentions · 2026-07-06: 1Mentions · 2026-07-16: 3PoC Mentioned / Linked · 2026-07-16: 3Exploit Tool / Code · 2026-07-16: 2Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-06: 1Technical Details · 2026-07-01: 2Technical Details · 2026-07-02: 1Technical Details · 2026-07-06: 1Technical Details · 2026-07-16: 107-0107-0207-0607-16
Signal classification5 categories
Disclosure
228.6%
Patch
228.6%
Exploit
114.3%
General
114.3%
PoC
114.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-012
Disclosure2
2026-07-021
Patch1
2026-07-061
Patch1
2026-07-163
Exploit1General1PoC1
Full discourse7 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-58457 Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows network-adjacent attackers to exe… https://www.cve.org/CVERecord?id=CVE-2026-58457

    Post summary

    The post announces CVE‑2026‑58457, describing an unauthenticated OS command injection flaw in the Shenzhen Aitemi M300 Wi‑Fi Repeater, without mentioning any PoC, exploit code, patch, or active exploitation.

    01020680
    58.0K followersView on X
  • Jλckλι@J4ck3LSyN
    PoC

    PoC: https://github.com/J4ck3LSyN-Gen2/CVE-2026-58457/ https://t.co/2IrBUQ8u4K

    Post summary

    The tweet links directly to a public GitHub repository containing a proof of concept for CVE‑2026‑58457, indicating that exploit code is available.

    0002068
    438 followersView on X
  • Jλckλι@J4ck3LSyN
    Exploit

    CVE-2026-58457 PoC + Report + MSF Module + FoFA Unauthenticated OS Command Injection in Shenzhen Aitemi M300 Wi-Fi Repeater [PoC]: https://github.com/J4ck3LSyN-Gen2/CVE-2026-58457/ [Report+FOFA]: https://github.com/J4ck3LSyN-Gen2/Reports/blob/main/OS-IS-CVE-2026-58457-07-2026.md > Use Accordingly & Legally #CyberSecurity #InfoSec #RCE #CVE #PoC #CFSD https://t.co/0yq0l8jZqT

    Post summary

    The tweet divulges CVE-2026-58457, providing a publicly available PoC, a Metasploit module, and a report that describe an unauthenticated OS command injection flaw in a Wi‑Fi repeater.

    01010222
    380 followersView on X
  • Jλckλι@J4ck3LSyN
    General

    Possible CVE-2026-58457 PoC Coming Soon... idk yet... 🙃 https://t.co/M64xN8A6Bu

    Post summary

    The tweet hints at an upcoming proof of concept for CVE‑2026‑58457 but provides no concrete evidence or technical details.

    0101096
    380 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-58457 — CVSS 9.8/10 ██████████ Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/H0MnV7NDrf

    Post summary

    The tweet announces CVE‑2026‑58457, a critical unauthenticated OS command injection in a Shenzhen Aitemi M300 Wi‑Fi repeater, and urges users to apply the available patch.

    10000106
    63 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-58457 (CVSS 9.8) Shenzhen Aitemi M300 Wi-Fi Repeater vulnerable to unauthenticated OS command injection. Network-adjacent attackers can execute arbitrary commands with root access via smacfilter_conf handler. Patch immediately! #CVE #PatchNow https://t.co/VzTLfCuF2P

    Post summary

    The post highlights a critical OS command injection in the Shenzhen Aitemi M300 Wi‑Fi repeater, stressing that a patch is urgently needed.

    0000040
    64 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-58457 Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows network-adjacent attackers to exe… https://www.cve.org/CVERecord?id=CVE-2026-58457 ----- Traducción: CVE-2026-58457 She… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑58457, noting an unauthenticated OS command injection flaw in the Shenzhen Aitemi M300 Wi‑Fi repeater (model MT02).

    0000038
    90 followersView on X

Explore more