Security Advisory

CVE-2025-34151

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-08-07 16:45:06
Last updated 2025-12-01 16:31:46
Assigner VulnCheck
State PUBLISHED

Description

A command injection vulnerability exists in the passwd parameter of the PPPoE setup process on the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). The input is passed directly to system-level commands without sanitation, enabling unauthenticated attackers to achieve root-level code execution.