AI analysis
Xiiaozet LK100Wt devices contain an authentication weakness (CWE-288) in an administrative service that allows an attacker to bypass intended access controls. Per the CVSS 4.0 vector, the flaw is reachable over a network with no privileges required and no user interaction, meaning a remote attacker can trigger it directly against the service. A successful attacker gains the ability to execute commands on the device, which the vendor-advisory language indicates may lead to complete device compromise. Only owners and operators of Xiiaozet LK100Wt devices are affected, particularly any units whose administrative interface is reachable from untrusted networks. No public proof-of-concept or confirmed in-the-wild exploitation is known; the 0.7% EPSS probability and absence from CISA KEV indicate low near-term exploitation risk.
What to do: Check the CISA ICS advisory for the affected version range and apply the vendor's fixed firmware as soon as it is available; the data provided does not include fixed version numbers. Until patched, restrict network exposure: avoid port-forwarding the device to the internet, place it on an isolated VLAN or behind a firewall, and limit access to its administrative service. Review device logs for unexpected connections or unexplained configuration changes that could indicate attempted exploitation.
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.