AI analysis
CVE-2026-78037 is an OS command injection flaw (CWE-78) in the web-based management interface of the Xiiaozet LK100W. An attacker who has valid low-privileged credentials can send crafted input to the interface to execute arbitrary operating system commands on the device. Because the injected commands run with elevated privileges, a successful attack can expose sensitive information or lead to complete compromise of the device, which the CVSS 4.0 score of 8.7 (high) reflects with high confidentiality, integrity, and availability impact. Any organization running a Xiiaozet LK100W, especially where the management web interface is reachable from untrusted networks, is in the affected population. There is currently no public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at about 1.2%, so no exploitation is known at this time.
What to do: Check the CISA ICS advisory and Xiiaozet's advisories for the affected and fixed firmware versions and update the LK100W to the patched firmware as soon as it is available. In the meantime, restrict access to the device's web management interface to trusted management networks or VPN users, enforce strong unique administrator credentials, and review device logs for unexpected commands or configuration changes.
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise.