CVE-2026-78239

9.8

Xiiaozet · Xiiaozet LK100W

The Xiiaozet LK100W device contains an authentication bypass vulnerability, allowing unauthenticated remote attackers to enable restricted administrative services.

Executive summary

A critical authentication bypass in the Xiiaozet LK100W allows unauthorized remote attackers to enable administrative services, potentially leading to full device compromise.

Vulnerability

This vulnerability, categorized as CWE-306 (Missing Authentication for Critical Function), allows an unauthenticated remote attacker to invoke management functions that should be restricted. By bypassing necessary access controls, an attacker can activate administrative services on the device.

Business impact

The severity of this flaw is reflected in its CVSS score of 9.8, indicating a critical risk to organizational infrastructure. Successful exploitation could grant an attacker full control over the affected device, potentially leading to unauthorized data access, service disruption, or the device being leveraged as a pivot point within the internal network.

Remediation

Immediate Action: Update the Xiiaozet LK100W firmware to version 2.1.240 or later to remediate the authentication bypass.

Proactive Monitoring: Review system and access logs for unusual administrative service activation or unauthorized connection attempts from unknown IP addresses.

Compensating Controls: Deploy network-level access controls or a Web Application Firewall to restrict access to the device management interface to trusted management subnets only.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical nature of this vulnerability and the potential for total device compromise, immediate action is required. Organizations utilizing the Xiiaozet LK100W must prioritize the firmware update to version 2.1.240. If an immediate update is not feasible, the device should be isolated from public-facing networks until the patch is applied.

More Xiiaozet CVEs

Sources

Originally found and disclosed by Byron Guernsey of Okachobi, LLC reported this vulnerability to CISA., per the CVE Program record.