ZeroHour

CVE-2026-78239

Missing Authentication on Xiiaozet LK100W Exposes Critical Management Function

CVSS 4.0
9.3 critical
EPSS
<1%p44
Published
()
Modified
AI analysis

Xiiaozet LK100W exposes a critical management function that can be reached over the network without any authentication (CWE-306), letting an unauthenticated remote attacker enable administrative services that should be restricted. The flaw is triggered simply by sending a request to the exposed management function, requiring no credentials, privileges, or user interaction. A successful attacker can activate privileged management services and gain unauthorized access to the device, with high potential impact on its confidentiality, integrity, and availability. Any deployment running an LK100W, especially one reachable from untrusted networks, is potentially affected; the advisory was coordinated by CISA ICS-CERT. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS assigns roughly a 0.6% probability of exploitation within 30 days.

What to do: Restrict network access to the LK100W management interface (firewall rules, ACLs, or an isolated management VLAN) and check whether administrative services were enabled unexpectedly on exposed units. Apply the latest vendor firmware as soon as Xiiaozet publishes a fix, and monitor the CISA ICS-CERT advisory for affected/fixed version details, which are not yet specified in the available data.

Affected
Xiiaozet LK100W
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. Successful exploitation may permit unauthorized access to the device.

Weakness
CWE-306
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Xiiaozet LK100W

CISA warns of three flaws, including OS command injection, in Xiiaozet LK100W devices before firmware 2.1.240 that allow attackers to take full control of the device.

CISA published ICS advisory ICSA-26-239-01 covering three vulnerabilities (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943) in Xiiaozet LK100W devices running firmware below 2.1.240. The issues include OS command injection, missing authentication for critical functions, and authentication bypass via an alternate path, rated CVSS v3 9.8. Successful exploitation allows an attacker to take control of the device. The China-based vendor's equipment is deployed worldwide, including information technology critical infrastructure sectors.