CISA Flags Three Xiiaozet LK100W Firmware Flaws
Two of the three vulnerabilities are remotely exploitable without credentials, but one requires authentication, and the vendor has published a fix.
TL;DR
CISA published ICS advisory ICSA-26-239-01 covering three vulnerabilities in Xiiaozet LK100W devices running firmware below version 2.1.240. The most severe (CVE-2026-78239 (missing authentication for critical function) and CVE-2026-76943 (authentication bypass)) each carry a CVSS v3.1 score of 9.8 and can be exploited remotely without credentials. CVE-2026-78037, an OS command injection with a CVSS v3.1 score of 8.8, requires authentication. Xiiaozet recommends updating to v2.1.240. No active exploitation has been reported to CISA, and no federal deployment deadline accompanies the advisory.
The advisory, published August 27, covers a single device family (the Xiiaozet LK100W) deployed worldwide in the information technology sector. CISA classifies all three vulnerabilities as exploitable remotely with low attack complexity.
CVE-2026-78239 is the most straightforward: a critical management function in the web-based interface can be invoked without any authentication at all. An attacker who reaches the device over the network can enable administrative services that should require credentials. CVE-2026-76943 sits alongside it, an authentication bypass that lets an attacker sidestep access controls on an administrative service, potentially gaining command execution capabilities. Both score 9.8 under CVSS v3.1 and 9.3 under CVSS v4.0.
The third vulnerability, CVE-2026-78037, is an OS command injection in the same management interface. It carries a CVSS v3.1 score of 8.8, lower than the other two because it requires authentication. An attacker who already has legitimate (or illicitly obtained) credentials could use it to execute arbitrary OS commands with elevated privileges.
Xiiaozet's recommended mitigation is updating firmware to version 2.1.240. The advisory does not describe workarounds or compensating controls for organizations that cannot apply the update immediately.
CISA's standard ICS advisory language reminds operators to minimize network exposure for control system devices and keep them off the public internet. For an LK100W sitting on a flat network reachable from the internet, the two credential-free vulnerabilities represent a credible path to device compromise. The advisory notes no known public exploitation of these specific vulnerabilities as of publication.
Published ·Deep Fathom