← Back to overview

CVE-2026-78037 describes an OS command injection vulnerability affecting the Xiiaozet LK100W device through its web-based management interface. An authenticated attacker can exploit this flaw to execute arbitrary operating system commands with elevated privileges. Successful exploitation may lead to unauthorized access to sensitive information or complete device compromise. The vulnerability requires authentication, limiting the attack surface but not eliminating the risk from insider threats or compromised credentials. The issue has been reported via NVD and is accompanied by a CISA ICS advisory (ICSA-26-239-01), indicating relevance to operational technology and industrial control system environments. The CSAF advisory file is also available through CISA's GitHub repository.

Affected products

  • Xiiaozet LK100W

Related CVE's

  • CVE-2026-78037

Categories

  • Critical Infrastructure
  • Mobile & IoT
  • Network Infrastructure