TL;DR
The Cybersecurity and Infrastructure Security Agency released an advisory detailing three critical Xiiaozet LK100W vulnerabilities. These security flaws allow remote attackers to bypass authentication and execute arbitrary operating system commands. Administrators should update their devices to firmware version 2.1.240 immediately to mitigate these risks.
- Product: Xiiaozet LK100W
- Vulnerabilities: 3 flaws (CVE-2026-78239, CVE-2026-76943, CVE-2026-78037)
- Highest severity: 9.8 (Critical · CVSSv3)
- Worst impact: Missing Authentication for Critical Function
- Status: No confirmed exploitation yet; patches available
- Action: Update to 2.1.240 now
| CVE | CVSS | Fixed in | Status |
|---|
Why the Vulnerabilities Matter
These security flaws carry significant risk for industrial and IT networks worldwide. According to CISA, “Successful exploitation of these vulnerabilities could allow an attacker to take control over the device.” Two flaws carry critical CVSS base scores of 9.8, presenting severe risks to device integrity. Therefore, unauthenticated attackers could compromise connected network environments without user interaction.
Currently, CISA has not reported specific deployment numbers, although these devices operate globally across critical infrastructure. Fortunately, CISA confirmed that “No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.” Researchers have also not released any public proof-of-concept exploits.
How the Attacks Work
The issues involve authentication failures and command processing weaknesses. For CVE-2026-78239, the device exposes a critical management function without authentication. Consequently, a remote attacker can enable restricted administrative services directly.
Similarly, CVE-2026-76943 introduces an authentication bypass within an administrative channel. This flaw lets attackers interact with privileged services to obtain command execution. Additionally, CVE-2026-78037 involves an improper neutralization flaw in the web management interface. An authenticated attacker can inject operating system commands with elevated privileges.
Affected Versions and Remediation
Impacted Products
These Xiiaozet LK100W vulnerabilities affect all firmware versions prior to 2.1.240.
Mitigation Steps
Xiiaozet recommends updating all devices to version 2.1.240 or later. Furthermore, administrators should isolate control devices behind firewalls and disable internet accessibility.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!