Description
Xiiaozet LK100Wt contains an authentication weakness within an
administrative service that may allow an attacker to bypass intended
access controls and obtain command execution capabilities. Successful
exploitation could allow unauthorized interaction with privileged
functionality and may lead to complete device compromise.
Published: 2026-08-27
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an authentication weakness in the administrative service of the Xiiaozet LK100W. It enables an attacker to bypass intended access controls and gain command execution capabilities on the device, potentially leading to full device compromise.

Affected Systems

The affected product is the Xiiaozet LK100W by Xiiaozet. No specific firmware or hardware revisions are listed, so all instances running this model are considered at risk until updated.

Risk and Exploitability

The CVSS score of 9.3 reflects a critical severity. The EPSS score is not available, so the current likelihood of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The attack vector most likely involves network access to the administrative service, though no explicit vector is stated in the description and is inferred from the nature of the service.

Generated by OpenCVE AI on August 28, 2026 at 08:14 UTC.

Remediation

Vendor Solution

Xiiaozet recommends users update to v2.1.240.


OpenCVE Recommended Actions

  • Apply the Xiiaozet update v2.1.240
  • Restrict network access to the administrative interface to trusted IP addresses or subnets
  • Enable detailed logging for authentication attempts and review logs regularly for unauthorized activity

Generated by OpenCVE AI on August 28, 2026 at 08:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Xiiaozet
Xiiaozet xiiaozet Lk100w
Vendors & Products Xiiaozet
Xiiaozet xiiaozet Lk100w

Fri, 28 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.
Title Xiiaozet LK100W Authentication Bypass Using an Alternate Path or Channel
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Xiiaozet Xiiaozet Lk100w
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-28T14:13:50.949Z

Reserved: 2026-08-25T15:37:54.554Z

Link: CVE-2026-76943

cve-icon Vulnrichment

Updated: 2026-08-28T14:04:23.561Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T00:18:15.343

Modified: 2026-09-03T17:45:20.840

Link: CVE-2026-76943

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T16:13:21Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel