← Terug naar overzicht

CISA published an ICS advisory for the Xiiaozet LK100W device affecting versions prior to 2.1.240. Three vulnerabilities were identified: CVE-2026-78037 (OS Command Injection via web management interface, CVSS 8.8), CVE-2026-78239 (Missing Authentication for Critical Function, CVSS 9.8), and CVE-2026-76943 (Authentication Bypass via Alternate Path or Channel, CVSS 9.8). Successful exploitation could allow an attacker to take complete control of the device. The vulnerabilities affect the Information Technology critical infrastructure sector and are deployed worldwide. The vendor, headquartered in China, recommends updating to firmware version v2.1.240. No known public exploitation has been reported at this time. Byron Guernsey of Okachobi, LLC reported these vulnerabilities to CISA.

Affected products

  • Xiiaozet LK100W <2.1.240

Related CVE's

  • CVE-2026-76943
  • CVE-2026-78037
  • CVE-2026-78239

Categories

  • Critical Infrastructure
  • Identity & Access
  • Mobile & IoT
  • Network Infrastructure