Authentication Weakness in Xiiaozet LK100Wt's Administrative Service
CVE-2026-76943

9.3CRITICAL

Key Information:

Vendor

Xiiaozet

Vendor
CVE Published:
27 August 2026

What is CVE-2026-76943?

The Xiiaozet LK100Wt device has a critical authentication vulnerability within its administrative service, potentially allowing attackers to circumvent established access controls. This weakness could enable unauthorized users to execute commands and interact with privileged functions, ultimately leading to a full compromise of the device. Organizations using the LK100Wt should take immediate steps to apply available patches and secure their systems against potential exploitation.

Affected Version(s)

Xiiaozet LK100W 0 < 2.1.240

Xiiaozet LK100W 2.1.240

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Byron Guernsey of Okachobi, LLC reported this vulnerability to CISA.
.