Impact
Xiiaozet LK100W exposes a critical management function that can be invoked without authentication. A remote attacker could enable administrative services that should be restricted, potentially allowing unauthorized access to the device. The flaw falls under CWE‑306, representing an authentication bypass.
Affected Systems
This vulnerability affects Xiiaozet LK100W devices, specifically firmware versions prior to v2.1.240.
Risk and Exploitability
With a CVSS score of 9.3 the risk is high. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Because the exposed function is reachable remotely, an attacker only needs network access to the device and can trigger the function, bypassing any credentials and enabling privileged services.
OpenCVE Enrichment