CVE-2026-78239: Xiiaozet LK100W

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. Successful exploitation may permit unauthorized access to the device.

Affected products

  • Xiiaozet Xiiaozet LK100W: before 2.1.240 (fixed in 2.1.240)

Published 2026-08-28. Last modified 2026-08-31.