<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>LK100W - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/lk100w/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 27 Aug 2026 16:06:09 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/lk100w/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical Vulnerabilities in Xiiaozet LK100W</title><link>https://feed.craftedsignal.io/briefs/2026-08-xiiaozet-lk100w/</link><pubDate>Thu, 27 Aug 2026 16:06:09 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-xiiaozet-lk100w/</guid><description>Xiiaozet LK100W devices running firmware prior to v2.1.240 are vulnerable to multiple high-severity flaws, including OS command injection and authentication bypass, which could allow remote attackers to achieve full device compromise.</description><content:encoded><![CDATA[<p>Xiiaozet LK100W devices running firmware versions earlier than 2.1.240 are affected by a suite of critical vulnerabilities (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943). These vulnerabilities collectively allow for authentication bypass, unauthorized invocation of critical management functions, and OS command injection via the web-based management interface. An attacker can leverage these flaws to execute arbitrary operating system commands with elevated privileges, potentially resulting in complete device takeover. These devices are used in Information Technology infrastructure globally. There is currently no report of active exploitation in the wild, but the high CVSS scores and the nature of the vulnerabilities - specifically the ability for unauthenticated remote code execution - pose a significant risk to affected organizations.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities allows an attacker to achieve full device compromise, potentially enabling data exfiltration, lateral movement within the network, or the ability to disrupt critical IT operations. The vulnerabilities affect Xiiaozet LK100W devices deployed globally, placing Information Technology infrastructure at risk. If exploited, an attacker could gain persistent access to the management environment, undermining the integrity and confidentiality of the entire device.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all Xiiaozet LK100W devices to firmware version 2.1.240 immediately to address CVE-2026-78037, CVE-2026-78239, and CVE-2026-76943.</li>
<li>Restrict network access to the web-based management interface of all Xiiaozet LK100W devices, ensuring they are not exposed directly to the internet.</li>
<li>Isolate control system networks containing these devices behind firewalls and ensure only authorized personnel can access the management interfaces via secure methods such as VPNs.</li>
<li>Implement monitoring on network egress and ingress traffic to identify unusual activity originating from or directed toward these devices, especially focusing on unauthorized HTTP requests to management endpoints.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>ics</category><category>cve</category><category>rce</category><category>authentication-bypass</category></item></channel></rss>