IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Xiiaozet LK100W

CRITICAL
CVSS 9.8
Date 2026-08-27T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could allow an attacker to take control over the device.

// Vulnerabilities (3)

CVE ID CVSS Score Severity Description
CVE-2026-78239 9.8 critical
Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. Successful exploitation may permit unauthorized access to the device.
CVE-2026-78037 8.8 high
Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise.
CVE-2026-76943 9.8 critical
Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.

// Remediations (1)

Mitigation: Xiiaozet recommends users update to v2.1.240.
Xiiaozet recommends users update to v2.1.240.

// References