Xiiaozet LK100W
CISA warns of three flaws, including OS command injection, in Xiiaozet LK100W devices before firmware 2.1.240 that allow attackers to take full control of the device.
CISA published ICS advisory ICSA-26-239-01 covering three vulnerabilities (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943) in Xiiaozet LK100W devices running firmware below 2.1.240. The issues include OS command injection, missing authentication for critical functions, and authentication bypass via an alternate path, rated CVSS v3 9.8. Successful exploitation allows an attacker to take control of the device. The China-based vendor's equipment is deployed worldwide, including information technology critical infrastructure sectors.
- CVSS 9.8 flaw set enables full device takeover
- Weaknesses: OS command injection, missing authentication, authentication bypass
- Fixed in firmware 2.1.240 or later
- Deployed worldwide across IT critical infrastructure
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-76943 | Authentication Bypass Enables Remote Command Execution in Xiiaozet LK100Wt Xiiaozet LK100Wt devices contain an authentication weakness (CWE-288) in an administrative service that allows an attacker to bypass intended access controls. Per the CVSS 4.0 vector, the flaw is reachable over a network with no privileges required and no user interaction, meaning a remote attacker can trigger it directly against the service. A successful attacker gains the ability to execute commands on the device, which the vendor-advisory language indicates may lead to complete device compromise. Only owners and operators of Xiiaozet LK100Wt devices are affected, particularly any units whose administrative interface is reachable from untrusted networks. No public proof-of-concept or confirmed in-the-wild exploitation is known; the 0.7% EPSS probability and absence from CISA KEV indicate low near-term exploitation risk. Do: Check the CISA ICS advisory for the affected version range and apply the vendor's fixed firmware as soon as it is available; the data provided does not include fixed version numbers. Until patched, restrict network exposure: avoid port-forwarding the device to the internet, place it on an isolated VLAN or behind a firewall, and limit access to its administrative service. Review device logs for unexpected connections or unexplained configuration changes that could indicate attempted exploitation. | 9.3 | <1% |
| — | ||
| CVE-2026-78037 | Authenticated OS Command Injection in Xiiaozet LK100W Web Interface CVE-2026-78037 is an OS command injection flaw (CWE-78) in the web-based management interface of the Xiiaozet LK100W. An attacker who has valid low-privileged credentials can send crafted input to the interface to execute arbitrary operating system commands on the device. Because the injected commands run with elevated privileges, a successful attack can expose sensitive information or lead to complete compromise of the device, which the CVSS 4.0 score of 8.7 (high) reflects with high confidentiality, integrity, and availability impact. Any organization running a Xiiaozet LK100W, especially where the management web interface is reachable from untrusted networks, is in the affected population. There is currently no public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at about 1.2%, so no exploitation is known at this time. Do: Check the CISA ICS advisory and Xiiaozet's advisories for the affected and fixed firmware versions and update the LK100W to the patched firmware as soon as it is available. In the meantime, restrict access to the device's web management interface to trusted management networks or VPN users, enforce strong unique administrator credentials, and review device logs for unexpected commands or configuration changes. | 8.7 | 1% |
| — | ||
| CVE-2026-78239 | Missing Authentication on Xiiaozet LK100W Exposes Critical Management Function Xiiaozet LK100W exposes a critical management function that can be reached over the network without any authentication (CWE-306), letting an unauthenticated remote attacker enable administrative services that should be restricted. The flaw is triggered simply by sending a request to the exposed management function, requiring no credentials, privileges, or user interaction. A successful attacker can activate privileged management services and gain unauthorized access to the device, with high potential impact on its confidentiality, integrity, and availability. Any deployment running an LK100W, especially one reachable from untrusted networks, is potentially affected; the advisory was coordinated by CISA ICS-CERT. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS assigns roughly a 0.6% probability of exploitation within 30 days. Do: Restrict network access to the LK100W management interface (firewall rules, ACLs, or an isolated management VLAN) and check whether administrative services were enabled unexpectedly on exposed units. Apply the latest vendor firmware as soon as Xiiaozet publishes a fix, and monitor the CISA ICS-CERT advisory for affected/fixed version details, which are not yet specified in the available data. | 9.3 | <1% |
| — |
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to take control over the device. The following versions of Xiiaozet LK100W are affected: LK100W <2.1.240 (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943) CVSS Vendor Equipment Vulnerabilities v3 9.8 Xiiaozet Xiiaozet LK100W Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Missing Authentication for Critical Function, Authentication Bypass Using an Alternate Path or Channel Background Critical Infrastructure Sectors: Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All…
This source does not provide full text. Read it at cisa.gov.