Xiiaozet LK100W is vulnerable to OS command injection through its
web-based management interface. An authenticated attacker may be able to
execute arbitrary operating system commands with elevated privileges,
potentially resulting in unauthorized access to sensitive information or
complete device compromise.
web-based management interface. An authenticated attacker may be able to
execute arbitrary operating system commands with elevated privileges,
potentially resulting in unauthorized access to sensitive information or
complete device compromise.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Xiiaozet recommends users update to v2.1.240.
Workaround
No workaround given by the vendor.
References
History
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise. | |
| Title | Xiiaozet LK100W OS Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-08-27T21:46:32.067Z
Reserved: 2026-08-25T15:37:54.537Z
Link: CVE-2026-78037
No data.
Status : Received
Published: 2026-08-28T00:18:16.063
Modified: 2026-08-28T00:18:16.063
Link: CVE-2026-78037
No data.
OpenCVE Enrichment
No data.
Weaknesses