Xiiaozet LK100W
CISA warns of three flaws, including OS command injection, in Xiiaozet LK100W devices before firmware 2.1.240 that allow attackers to take full control of the device.
CISA published ICS advisory ICSA-26-239-01 covering three vulnerabilities (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943) in Xiiaozet LK100W devices running firmware below 2.1.240. The issues include OS command injection, missing authentication for critical functions, and authentication bypass via an alternate path, rated CVSS v3 9.8. Successful exploitation allows an attacker to take control of the device. The China-based vendor's equipment is deployed worldwide, including information technology critical infrastructure sectors.