CVE-2025-34152 is an unauthenticated operating system command injection vulnerability in the Shenzhen Aitemi M300 Wi-Fi Repeater, hardware model MT02. The flaw is exposed through the 'time' parameter of the '/protocol.csp?' endpoint. User-supplied input is passed to the device's internal date-setting functionality and processed by the underlying date '-s' command without sufficient sanitization or neutralization of shell metacharacters. Because the vulnerable endpoint is reachable without authentication, a remote attacker can inject arbitrary commands directly through crafted HTTP requests. The injection path is notable because exploitation does not require a reboot and does not disrupt the HTTP service, enabling remote compromise with minimal visible operational impact or configuration change indications.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a working exploit for CVE-2025-34152, targeting the Shenzhen Aitemi M300 Wi-Fi Repeater. The exploit is implemented in Go (CVE-2025-34152.go) and enables unauthenticated remote code execution by sending a crafted POST request to the device's /protocol.csp endpoint. The payload establishes a reverse shell from the device to the attacker's machine using netcat and a named pipe. The exploit does not require authentication, does not reboot the device, and is suitable for automated exploitation. The README provides version information, remediation advice, and usage instructions. The repository is structured simply, with the main exploit code, a README, and a license file. No detection scripts or fake code are present; this is a functional exploit.
This repository contains a single Go exploit targeting CVE-2025-34152, an unauthenticated remote code execution vulnerability in the Shenzhen Aitemi M300 Wi-Fi Repeater. The exploit does not require authentication and is designed for automated exploitation at scale. It sends a crafted POST request to the /protocol.csp endpoint on the target device, injecting a shell command that establishes a reverse shell to the attacker's machine using netcat and a named pipe. The exploit is operational, requiring the attacker to specify the target URL, their own IP, and a listening port. The code also supports optional proxying of requests. The repository is well-structured, with clear usage instructions and comments, and is focused solely on exploitation (not detection or scanning).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability exploited by the Dysphoria botnet to compromise devices.
A recently disclosed IoT-device vulnerability reportedly used by the Dysphoria botnet for propagation.
An unauthenticated remote code execution vulnerability in the Aitemi M300, referenced as a Metasploit module PR.
A vulnerability in Shenzhen Aitemi devices running lighttpd, targeted by the frost malware.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.