← Back to Feed

Xiiaozet LK100W

CVE-2026-78037CVE-2026-78239CVE-2026-76943

August 27, 2026 · CISA (US-CERT) · Severity: CRITICAL

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to take control over the device. The following versions of Xiiaozet LK100W are affected: LK100W <2.1.240 (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943) CVSS Vendor Equipment Vulnerabilities v3 9.8 Xiiaozet Xiiaozet LK100W Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Missing Authentication for Critical Function, Authentication Bypass Using an Alternate Path or Channel Background Critical Infrastructure Sectors: Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-78037 Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise. View CVE Details Affected Products Xiiaozet LK100W Vendor:Xiiaozet Product Version:Xiiaozet LK100W: <2.1.240 Product Status:known_affected Remediations MitigationXiiaozet recommends users update to v2.1.240. Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-78239 Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. Successful exploitation may permit unauthorized access to the device. View CVE Details Affected Products Xiiaozet LK100W Vendor:Xiiaozet Product Version:Xiiaozet LK100W: <2.1.240 Product...

Key Takeaways

  • CISA published an advisory for Xiiaozet LK100W urging users to apply vendor patches and mitigations.
  • The advisory covers 3 vulnerabilities in Xiiaozet LK100W that require immediate patching.
  • Active exploitation of vulnerabilities in Xiiaozet LK100W has been reported, making patching urgent for affected organizations.
☕ Buy a Coffee