Xiiaozet Lk100W vulnerabilities
3 known vulnerabilities affecting xiiaozet/xiiaozet_lk100w.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1
Vulnerabilities
Page 1 of 1
CVE-2026-78239P2CRITICALCVSS 9.8fixed in 2.1.2402026-08-28
CVE-2026-78239 [CRITICAL] CWE-306 CVE-2026-78239: Xiiaozet LK100W exposes a critical management function that can be invoked without authentication,
Xiiaozet LK100W exposes a critical management function that can be
invoked without authentication, allowing a remote attacker to enable
administrative services that should be restricted. Successful
exploitation may permit unauthorized access to the device.
nvd
CVE-2026-78037P2HIGHCVSS 8.8fixed in 2.1.2402026-08-28
CVE-2026-78037 [HIGH] CWE-78 CVE-2026-78037: Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. A
Xiiaozet LK100W is vulnerable to OS command injection through its
web-based management interface. An authenticated attacker may be able to
execute arbitrary operating system commands with elevated privileges,
potentially resulting in unauthorized access to sensitive information or
complete device compromise.
nvd
CVE-2026-76943P2CRITICALCVSS 9.8fixed in 2.1.2402026-08-28
CVE-2026-76943 [CRITICAL] CWE-288 CVE-2026-76943: Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allo
Xiiaozet LK100Wt contains an authentication weakness within an
administrative service that may allow an attacker to bypass intended
access controls and obtain command execution capabilities. Successful
exploitation could allow unauthorized interaction with privileged
functionality and may lead to complete device compromise.
nvd