← Terug naar overzicht

CVE-2026-78239 affects the Xiiaozet LK100W device, which exposes a critical management function that can be invoked without authentication. A remote attacker can exploit this flaw to enable administrative services that are intended to be restricted. Successful exploitation could allow unauthorized access to the device. The vulnerability is classified as critical severity. It has been documented by NVD and referenced in a CISA ICS advisory (ICSA-26-239-01). The issue falls under the category of missing authentication for critical functions. No user interaction is required for exploitation, making it particularly dangerous in internet-exposed deployments. Organizations using this device should apply mitigations or patches as directed by the vendor and CISA.

Affected products

  • Xiiaozet LK100W

Related CVE's

  • CVE-2026-78239

Categories

  • Critical Infrastructure
  • Identity & Access
  • Mobile & IoT
  • Zero-Day Vulnerabilities