CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Xiiaozet LK100W

criticalCVE-2026-78037CVE-2026-78239CVE-2026-76943
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to take control over the device. The following versions of Xiiaozet LK100W are affected: LK100W <2.1.240 (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943) CVSS Vendor Equipment Vulnerabilities v3 9.8 Xiiaozet Xiiaozet LK100W Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Missing Authentication for Critical Function, Authentication Bypass Using an Alternate Path or Channel Background Critical Infrastructure Sectors: Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-78037 Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise. View CVE Details Affected Products Xiiaozet LK100W Vendor: Xiiaozet Product Version: Xiiaozet LK100W: <2.1.240 Product Status: known_affected Remediations Mitigation Xiiaozet recommends users update to v2.1.240. Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-78239 Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. Successful exploitation may permit unauthorized access to the device. View CVE Details Affected Products Xiiaozet LK100W Vendor: Xiiaozet Product Version: Xiiaozet LK100W: <2.1.240 Product Status: known_affected Remediations Mitigation Xiiaozet recommends users update to v2.

CSIRTS triage

What
OS command injection, missing authentication for critical functions, and alternate authentication path bypass allow arbitrary command execution with elevated privilege.
Who is affected
Xiiaozet LK100W devices running firmware below 2.1.240 exposed to the management interface.
Urgency
Critical; attackers can take complete control of the device via unauthenticated OS command injection.
Action
Upgrade Xiiaozet LK100W firmware to version 2.1.240 or later immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch LK100W

Get an email when a new LK100W advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-08-27
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-01

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-78037coverage & exploitation statusNVD · CVE.org
CVE-2026-78239coverage & exploitation statusNVD · CVE.org
CVE-2026-76943coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Xiiaozet LK100W

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CISA Cybersecurity Advisories