VYPR
advisoryPublished Aug 27, 2026· 1 source

CISA Warns of Multiple Critical Vulnerabilities in Xiiaozet LK100W Devices

CISA has issued an advisory detailing three critical vulnerabilities in Xiiaozet LK100W devices, potentially allowing attackers to gain full control.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical advisory concerning multiple severe vulnerabilities affecting Xiiaozet LK100W devices, versions prior to 2.1.240. These vulnerabilities, if successfully exploited, could grant attackers complete control over the affected devices, posing a significant risk to industrial control systems and critical infrastructure.

The identified vulnerabilities include OS command injection (CVE-2026-78037), missing authentication for critical functions (CVE-2026-78239), and an authentication bypass flaw (CVE-2026-76943). The combination of these weaknesses presents a serious threat, as they could allow remote attackers to execute arbitrary commands, elevate privileges, and potentially compromise the entire device.

CVE-2026-78037, an OS command injection vulnerability, resides within the device's web-based management interface. An authenticated attacker could leverage this flaw to inject and execute operating system commands with elevated privileges. This could lead to unauthorized access to sensitive information or a complete takeover of the device.

Further compounding the risk is CVE-2026-78239, which involves missing authentication for critical functions. This vulnerability allows a remote attacker to invoke essential management functions without proper authentication, potentially enabling administrative services that should be strictly restricted. Successful exploitation could result in unauthorized access to the device's core functionalities.

Adding to the severity, CVE-2026-76943 is an authentication bypass vulnerability. This flaw exists within an administrative service and could permit an attacker to circumvent intended access controls. This bypass could grant attackers command execution capabilities, leading to unauthorized interaction with privileged functions and a potential full device compromise.

These vulnerabilities have been assigned high and critical CVSS v3.1 base scores, with CVE-2026-78239 and CVE-2026-76943 both receiving a critical score of 9.8. The CVSS v4.0 scores are also alarmingly high, indicating a severe risk to systems employing these devices.

Xiiaozet has released version 2.1.240 of the LK100W firmware, which addresses these vulnerabilities. CISA strongly recommends that users update to this latest version immediately. Additionally, CISA advises organizations to implement defensive measures to minimize the risk of exploitation, such as minimizing network exposure of control system devices, isolating them behind firewalls, and using secure remote access methods like VPNs, ensuring those are also kept up-to-date.

While no known public exploitation has been reported to CISA at this time, the critical nature of these vulnerabilities underscores the importance of prompt patching and robust security practices within industrial environments. The widespread deployment of Xiiaozet LK100W devices, particularly in critical infrastructure sectors and across various countries, highlights the potential impact should these flaws be actively exploited.

Synthesized by Vypr AI