Description
Xiiaozet LK100Wt contains an authentication weakness within an
administrative service that may allow an attacker to bypass intended
access controls and obtain command execution capabilities. Successful
exploitation could allow unauthorized interaction with privileged
functionality and may lead to complete device compromise.
Published: 2026-08-27
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an authentication weakness in the administrative service of the Xiiaozet LK100W. It enables an attacker to bypass intended access controls and gain command execution capabilities on the device, potentially leading to full device compromise.

Affected Systems

The affected product is the Xiiaozet LK100W by Xiiaozet. No specific firmware or hardware revisions are listed, so all instances running this model are considered at risk until updated.

Risk and Exploitability

The CVSS score of 9.3 reflects a critical severity. The EPSS score is not available, so the current likelihood of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The attack vector most likely involves network access to the administrative service, though no explicit vector is stated in the description and is inferred from the nature of the service.

Generated by OpenCVE AI on August 28, 2026 at 08:14 UTC.

Remediation

Vendor Solution

Xiiaozet recommends users update to v2.1.240.


OpenCVE Recommended Actions

  • Apply the Xiiaozet update v2.1.240
  • Restrict network access to the administrative interface to trusted IP addresses or subnets
  • Enable detailed logging for authentication attempts and review logs regularly for unauthorized activity

Generated by OpenCVE AI on August 28, 2026 at 08:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.
Title Xiiaozet LK100W Authentication Bypass Using an Alternate Path or Channel
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-27T21:50:49.310Z

Reserved: 2026-08-25T15:37:54.554Z

Link: CVE-2026-76943

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T00:18:15.343

Modified: 2026-08-28T00:18:15.343

Link: CVE-2026-76943

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T08:15:06Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel