CVE-2026-76943: Xiiaozet LK100W

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.

Affected products

  • Xiiaozet Xiiaozet LK100W: before 2.1.240 (fixed in 2.1.240)

Published 2026-08-28. Last modified 2026-09-03.