CVE-2026-78037
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Xiiaozet | Xiiaozet LK100W | 0 < 2.1.240 | affected |
| Xiiaozet | Xiiaozet LK100W | 2.1.240 | unaffected |
Weaknesses
- CWE-78: CWE-78
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-01
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-01.json
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.