CVE-2026-78239: Xiiaozet LK100W
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. Successful exploitation may permit unauthorized access to the device.
Affected products
- Xiiaozet Xiiaozet LK100W: before 2.1.240 (fixed in 2.1.240)
Published 2026-08-28. Last modified 2026-08-31.