CVE-2026-76943
9.8Xiiaozet · LK100W
The Xiiaozet LK100W administrative service contains an authentication weakness that allows unauthenticated attackers to bypass access controls and achieve remote command execution.
Executive summary
A critical authentication bypass in the Xiiaozet LK100W administrative service enables unauthenticated remote command execution, potentially leading to total device compromise.
Vulnerability
The device suffers from an authentication bypass vulnerability (CWE-288) within an administrative service. This flaw allows an unauthenticated attacker to interact with privileged functionality, resulting in arbitrary command execution.
Business impact
The ability for an unauthenticated attacker to execute commands with administrative privileges presents a severe risk to organizational operations. Successful exploitation can lead to full device compromise, unauthorized data access, and the potential for the device to be used as a pivot point for further lateral movement within the network. Given the CVSS score of 9.8, this vulnerability is classified as critical and requires immediate attention to prevent operational disruption.
Remediation
Immediate Action: Update the Xiiaozet LK100W firmware to version 2.1.240 or later immediately.
Proactive Monitoring: Monitor device access logs for unusual administrative login attempts or unexpected command execution patterns originating from unauthorized network segments.
Compensating Controls: Implement strict network segmentation and utilize a firewall to restrict access to the administrative service to known, trusted management IP addresses.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability represents a critical security risk due to the lack of required authentication for administrative command execution. Organizations utilizing the Xiiaozet LK100W must prioritize the application of firmware version 2.1.240 across all affected assets to eliminate this exposure. Failure to patch may leave devices vulnerable to complete remote takeover by unauthenticated attackers.
More Xiiaozet CVEs
Sources
Originally found and disclosed by Byron Guernsey of Okachobi, LLC reported this vulnerability to CISA., per the CVE Program record.