CVE-2026-78037: Xiiaozet LK100W

High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.

Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise.

Affected products

  • Xiiaozet Xiiaozet LK100W: before 2.1.240 (fixed in 2.1.240)

Published 2026-08-28. Last modified 2026-08-31.