AI analysis
Xiiaozet LK100W exposes a critical management function that can be reached over the network without any authentication (CWE-306), letting an unauthenticated remote attacker enable administrative services that should be restricted. The flaw is triggered simply by sending a request to the exposed management function, requiring no credentials, privileges, or user interaction. A successful attacker can activate privileged management services and gain unauthorized access to the device, with high potential impact on its confidentiality, integrity, and availability. Any deployment running an LK100W, especially one reachable from untrusted networks, is potentially affected; the advisory was coordinated by CISA ICS-CERT. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS assigns roughly a 0.6% probability of exploitation within 30 days.
What to do: Restrict network access to the LK100W management interface (firewall rules, ACLs, or an isolated management VLAN) and check whether administrative services were enabled unexpectedly on exposed units. Apply the latest vendor firmware as soon as Xiiaozet publishes a fix, and monitor the CISA ICS-CERT advisory for affected/fixed version details, which are not yet specified in the available data.
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. Successful exploitation may permit unauthorized access to the device.