CVE-2026-76943
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Xiiaozet | Xiiaozet LK100W | 0 < 2.1.240 | affected |
| Xiiaozet | Xiiaozet LK100W | 2.1.240 | unaffected |
Weaknesses
- CWE-288: CWE-288
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-01
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-01.json
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.