ZeroHour

CVE-2026-76943

Authentication Bypass Enables Remote Command Execution in Xiiaozet LK100Wt

CVSS 4.0
9.3 critical
EPSS
<1%p50
Published
()
Modified
AI analysis

Xiiaozet LK100Wt devices contain an authentication weakness (CWE-288) in an administrative service that allows an attacker to bypass intended access controls. Per the CVSS 4.0 vector, the flaw is reachable over a network with no privileges required and no user interaction, meaning a remote attacker can trigger it directly against the service. A successful attacker gains the ability to execute commands on the device, which the vendor-advisory language indicates may lead to complete device compromise. Only owners and operators of Xiiaozet LK100Wt devices are affected, particularly any units whose administrative interface is reachable from untrusted networks. No public proof-of-concept or confirmed in-the-wild exploitation is known; the 0.7% EPSS probability and absence from CISA KEV indicate low near-term exploitation risk.

What to do: Check the CISA ICS advisory for the affected version range and apply the vendor's fixed firmware as soon as it is available; the data provided does not include fixed version numbers. Until patched, restrict network exposure: avoid port-forwarding the device to the internet, place it on an isolated VLAN or behind a firewall, and limit access to its administrative service. Review device logs for unexpected connections or unexplained configuration changes that could indicate attempted exploitation.

Affected
Xiiaozet LK100Wt
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.

Weakness
CWE-288
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Xiiaozet LK100W

CISA warns of three flaws, including OS command injection, in Xiiaozet LK100W devices before firmware 2.1.240 that allow attackers to take full control of the device.

CISA published ICS advisory ICSA-26-239-01 covering three vulnerabilities (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943) in Xiiaozet LK100W devices running firmware below 2.1.240. The issues include OS command injection, missing authentication for critical functions, and authentication bypass via an alternate path, rated CVSS v3 9.8. Successful exploitation allows an attacker to take control of the device. The China-based vendor's equipment is deployed worldwide, including information technology critical infrastructure sectors.