CVE-2026-76943

9.8

Xiiaozet · LK100W

The Xiiaozet LK100W administrative service contains an authentication weakness that allows unauthenticated attackers to bypass access controls and achieve remote command execution.

Executive summary

A critical authentication bypass in the Xiiaozet LK100W administrative service enables unauthenticated remote command execution, potentially leading to total device compromise.

Vulnerability

The device suffers from an authentication bypass vulnerability (CWE-288) within an administrative service. This flaw allows an unauthenticated attacker to interact with privileged functionality, resulting in arbitrary command execution.

Business impact

The ability for an unauthenticated attacker to execute commands with administrative privileges presents a severe risk to organizational operations. Successful exploitation can lead to full device compromise, unauthorized data access, and the potential for the device to be used as a pivot point for further lateral movement within the network. Given the CVSS score of 9.8, this vulnerability is classified as critical and requires immediate attention to prevent operational disruption.

Remediation

Immediate Action: Update the Xiiaozet LK100W firmware to version 2.1.240 or later immediately.

Proactive Monitoring: Monitor device access logs for unusual administrative login attempts or unexpected command execution patterns originating from unauthorized network segments.

Compensating Controls: Implement strict network segmentation and utilize a firewall to restrict access to the administrative service to known, trusted management IP addresses.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability represents a critical security risk due to the lack of required authentication for administrative command execution. Organizations utilizing the Xiiaozet LK100W must prioritize the application of firmware version 2.1.240 across all affected assets to eliminate this exposure. Failure to patch may leave devices vulnerable to complete remote takeover by unauthenticated attackers.

More Xiiaozet CVEs

Sources

Originally found and disclosed by Byron Guernsey of Okachobi, LLC reported this vulnerability to CISA., per the CVE Program record.