High severity8.8NVD Advisory· Published Aug 28, 2026· Updated Aug 31, 2026
CVE-2026-78037
CVE-2026-78037
Description
Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2News mentions
2- Cisagov CSAF: Seven Vulnerabilities Disclosed Together Impact Xiiaozet and Ebyte DevicesVypr Intelligence · Aug 28, 2026
- Xiiaozet LK100WCISA ICS Advisories