CVE-2026-58457 carries a CVSS 3.1 base score of 9.8 against the M300 Wi-Fi Repeater MT02, a consumer Wi-Fi range extender manufactured by Shenzhen Aitemi E Commerce Co., Ltd. NVD classifies it as CWE-78 (OS Command Injection) and states the flaw is present in all firmware versions of the device — there is no version boundary because, per NVD’s record, no fix has been released. VulnCheck’s KEV feed reports the CVE as exploited, dated September 4, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-58457 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s description identifies the exact vulnerable code path: the device’s smacfilter_conf web handler builds a shell command with sprintf() using attacker-supplied input from the name, enable, or mac GET parameters, then passes that string to an internal function, doSystemCmdComlib(), which executes it via the device’s underlying uci (Unified Configuration Interface) shell tooling. None of the three parameters are sanitized before being embedded in the constructed command string, so an attacker who can reach the handler can inject arbitrary shell metacharacters and have them executed with whatever privileges the web-management process runs under.
NVD does not state an authentication requirement for reaching this handler, and the CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms no privileges or user interaction are needed — a remote, unauthenticated attacker who can reach the device’s management interface can trigger this directly.
Evidence and confidence
- Medium confidence — the CVSS 9.8 score, the vector, the CWE-78 classification, and the specific defect chain (
smacfilter_confhandler, the three vulnerable GET parameters,sprintf()command construction, execution viadoSystemCmdComlib()) all trace to NVD alone. The exploitation report traces to VulnCheck KEV alone. - Elevated exploitation probability — FIRST’s EPSS model scores this CVE at 0.02939, an 86.4th percentile score as of our ingestion — notably higher than most of the VulnCheck-only CVEs in our recent coverage, and consistent with a fully unauthenticated, low-complexity vulnerability in widely deployed consumer IoT hardware.
No field is in conflict between our two sources. NVD names no fixed version because, per its own record, all firmware versions are affected — there is currently no patched release to point to.
Why this matters
Consumer Wi-Fi extenders like the M300 are rarely monitored, rarely updated by their owners, and frequently left reachable on a home or small-office network with their management interface exposed to more of the network than the owner realizes. An unauthenticated, unpatched command-injection flaw in that class of device is a durable foothold: unlike enterprise infrastructure, nobody is watching for anomalous behavior on a $20 range extender, and the device may simply never be updated because Shenzhen Aitemi has not shipped a fix at all, per NVD’s record covering all firmware versions.
Because there is no patched version to move to, the only mitigation available today is network-level: restrict access to the device’s management interface to trusted hosts only, or, where the device’s role can be filled by other means, remove it from the network entirely.
Frequently Asked Questions
What is CVE-2026-58457?
A CVSS 9.8 OS command injection vulnerability (CWE-78) in the Shenzhen Aitemi M300 Wi-Fi Repeater MT02, allowing unauthenticated remote command execution via the smacfilter_conf web handler, present in all firmware versions per NVD.
Is CVE-2026-58457 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 4, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration.
Is there a firmware update that fixes this? No. NVD’s record states the vulnerability affects all firmware versions, meaning no patched release currently exists.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
What can I do if there’s no patch? Restrict network access to the device’s management interface to trusted hosts, or remove the device from the network if it can be replaced. NVD’s record gives no indication a vendor patch is forthcoming.
Severity, vector, weakness classification, and the full defect chain sourced from the National Vulnerability Database record for CVE-2026-58457. Exploitation status and the September 4, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.