Unauthorized Access Vulnerability in Xiiaozet LK100W Device
CVE-2026-78239

9.3CRITICAL

Key Information:

Vendor

Xiiaozet

Vendor
CVE Published:
27 August 2026

What is CVE-2026-78239?

The Xiiaozet LK100W device is vulnerable due to an improperly secured management function that can be accessed without authentication. This creates an opportunity for remote attackers to enable administrative services that should be properly restricted. Successful exploitation could lead to unauthorized access to the device, potentially compromising its functionality and security.

Affected Version(s)

Xiiaozet LK100W 0 < 2.1.240

Xiiaozet LK100W 2.1.240

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Byron Guernsey of Okachobi, LLC reported this vulnerability to CISA.
.