Impact
The vulnerability is an authentication weakness in the administrative service of the Xiiaozet LK100W. It enables an attacker to bypass intended access controls and gain command execution capabilities on the device, potentially leading to full device compromise.
Affected Systems
The affected product is the Xiiaozet LK100W by Xiiaozet. No specific firmware or hardware revisions are listed, so all instances running this model are considered at risk until updated.
Risk and Exploitability
The CVSS score of 9.3 reflects a critical severity. The EPSS score is not available, so the current likelihood of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The attack vector most likely involves network access to the administrative service, though no explicit vector is stated in the description and is inferred from the nature of the service.
OpenCVE Enrichment