CVE-2026-78037
published 2026-08-28CVE-2026-78037: Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary…
PriorityP265high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.87%
78.5th percentile
Xiiaozet LK100W is vulnerable to OS command injection through its
web-based management interface. An authenticated attacker may be able to
execute arbitrary operating system commands with elevated privileges,
potentially resulting in unauthorized access to sensitive information or
complete device compromise.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| xiiaozet | xiiaozet_lk100w | < 2.1.240 | 2.1.240 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface.
ghsa_unreviewed·2026-08-28
CVE-2026-78037 [HIGH] CWE-78 Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface.
Xiiaozet LK100W is vulnerable to OS command injection through its
web-based management interface. An authenticated attacker may be able to
execute arbitrary operating system commands with elevated privileges,
potentially resulting in unauthorized access to sensitive information or
complete device compromise.
VulDB
Xiiaozet LK100W up to 2.1.239 Web-based Management Interface os command injection
vuldb·2026-08-28·CVSS 8.8
CVE-2026-78037 [HIGH] Xiiaozet LK100W up to 2.1.239 Web-based Management Interface os command injection
A vulnerability was found in Xiiaozet LK100W up to 2.1.239 and classified as very critical. This affects an unknown part of the component Web-based Management Interface. Executing a manipulation can lead to os command injection.
This vulnerability is tracked as CVE-2026-78037. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-28
Published