What happened
CISA published an advisory on 2026-08-27 detailing three vulnerabilities in Xiiaozet LK100W. The vulnerabilities are identified as CVE-2026-78037, CVE-2026-78239, and CVE-2026-76943. They include improper neutralization of special elements used in an OS command (OS command injection), missing authentication for critical function, and authentication bypass using an alternate path or channel. Successful exploitation of these vulnerabilities could allow an attacker to take control over the device. The affected versions are LK100W <2.1.240. The CVSS v3 score is 9.8.
Why it matters
The Xiiaozet LK100W is deployed in the Information Technology critical infrastructure sector. The high CVSS score and the potential for full device takeover make these vulnerabilities critical. Organizations using affected versions should apply patches or mitigations as recommended by the vendor and CISA.