Skip to content
  • NVDA
  • AAPL
  • MSFT
  • AMD
  • TSLA

Xiiaozet LK100W Vulnerabilities Allow Device Takeover

CISA advisory reports three vulnerabilities in Xiiaozet LK100W, with a CVSS score of 9.8.

By TMRO Staff·1 min read

Key points

  • CISA advisory published 2026-08-27
  • Three CVEs: CVE-2026-78037, CVE-2026-78239, CVE-2026-76943
  • CVSS v3 score 9.8
  • Affects LK100W versions <2.1.240
  • Exploitation could allow device takeover

What happened

CISA published an advisory on 2026-08-27 detailing three vulnerabilities in Xiiaozet LK100W. The vulnerabilities are identified as CVE-2026-78037, CVE-2026-78239, and CVE-2026-76943. They include improper neutralization of special elements used in an OS command (OS command injection), missing authentication for critical function, and authentication bypass using an alternate path or channel. Successful exploitation of these vulnerabilities could allow an attacker to take control over the device. The affected versions are LK100W <2.1.240. The CVSS v3 score is 9.8.

Why it matters

The Xiiaozet LK100W is deployed in the Information Technology critical infrastructure sector. The high CVSS score and the potential for full device takeover make these vulnerabilities critical. Organizations using affected versions should apply patches or mitigations as recommended by the vendor and CISA.

Why it matters

The vulnerabilities affect a device used in the Information Technology critical infrastructure sector. With a high CVSS score and potential for full device takeover, these flaws pose a significant risk to organizations using the affected versions.

Sources

TMRO Report writes original coverage based on the material listed above.