CISA published an ICS advisory detailing three vulnerabilities in Xiiaozet LK100W devices running firmware versions prior to 2.1.240. The vulnerabilities include OS command injection, missing authentication for critical functions, and authentication bypass, which could allow unauthenticated remote attackers to achieve complete device compromise.
ICS advisory
4 posts
Xiiaozet LK100W (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943) PayRange API (CVE-2026-18965) CISA published an ICS advisory for CVE-2026-18965, a missing authorization vulnerability (CWE-862) in all versions of the PayRange API. The flaw exposes management endpoints without proper access controls, allowing remote attackers to disclose sensitive information about every device on the PayRange network, modify device settings to cause denial of service, or alter displayed images. The CVSS v3.1 score is 8.8 (HIGH). PayRange has not responded to CISA coordination efforts, leaving no vendor-supplied patch available.
Ebyte NE2-D11 (CVE-2026-73125, CVE-2026-73809, CVE-2026-73839 +8 more) CISA published an ICS advisory disclosing eleven vulnerabilities in the Ebyte NE2-D11 industrial gateway device running firmware FW-9167-0-11. Three CVEs are rated CVSS 9.8 Critical, covering missing authentication, client-side authentication bypass, and cleartext MQTT credential transmission. No patch is available; the vendor acknowledged the reports but has not provided remediation. Attackers can exploit these flaws remotely without authentication to gain administrative control, intercept credentials, hijack sessions, and disrupt device operation.
Siemens Parasolid (CVE-2026-64629) Siemens Parasolid V38.0 and V38.1 are affected by an out-of-bounds read vulnerability (CVE-2026-64629) that is triggered when the application parses specially crafted X_T format files. The flaw allows an attacker to crash the application or execute arbitrary code with the privileges of the current process. Siemens has released fixed versions V38.0.235 and V38.1.230.