CVE-2026-78239

Summary

Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. Successful exploitation may permit unauthorized access to the device.

Affected Software

VendorProductVersion RangeStatus
XiiaozetXiiaozet LK100W0 < 2.1.240affected
XiiaozetXiiaozet LK100W2.1.240unaffected

Weaknesses

  • CWE-306: CWE-306

References