CISA published an ICS advisory detailing three vulnerabilities in Xiiaozet LK100W devices running firmware versions prior to 2.1.240. The vulnerabilities include OS command injection, missing authentication for critical functions, and authentication bypass, which could allow unauthenticated remote attackers to achieve complete device compromise.
CVE-2026-78037
1 post
Xiiaozet LK100W (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943)