{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/xiiaozet/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["LK100W"],"_cs_severities":["critical"],"_cs_tags":["ics","cve","rce","authentication-bypass"],"_cs_type":"threat","_cs_vendors":["Xiiaozet"],"content_html":"\u003cp\u003eXiiaozet LK100W devices running firmware versions earlier than 2.1.240 are affected by a suite of critical vulnerabilities (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943). These vulnerabilities collectively allow for authentication bypass, unauthorized invocation of critical management functions, and OS command injection via the web-based management interface. An attacker can leverage these flaws to execute arbitrary operating system commands with elevated privileges, potentially resulting in complete device takeover. These devices are used in Information Technology infrastructure globally. There is currently no report of active exploitation in the wild, but the high CVSS scores and the nature of the vulnerabilities - specifically the ability for unauthenticated remote code execution - pose a significant risk to affected organizations.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows an attacker to achieve full device compromise, potentially enabling data exfiltration, lateral movement within the network, or the ability to disrupt critical IT operations. The vulnerabilities affect Xiiaozet LK100W devices deployed globally, placing Information Technology infrastructure at risk. If exploited, an attacker could gain persistent access to the management environment, undermining the integrity and confidentiality of the entire device.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Xiiaozet LK100W devices to firmware version 2.1.240 immediately to address CVE-2026-78037, CVE-2026-78239, and CVE-2026-76943.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the web-based management interface of all Xiiaozet LK100W devices, ensuring they are not exposed directly to the internet.\u003c/li\u003e\n\u003cli\u003eIsolate control system networks containing these devices behind firewalls and ensure only authorized personnel can access the management interfaces via secure methods such as VPNs.\u003c/li\u003e\n\u003cli\u003eImplement monitoring on network egress and ingress traffic to identify unusual activity originating from or directed toward these devices, especially focusing on unauthorized HTTP requests to management endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T16:06:09Z","date_published":"2026-08-27T16:06:09Z","id":"https://feed.craftedsignal.io/briefs/2026-08-xiiaozet-lk100w/","summary":"Xiiaozet LK100W devices running firmware prior to v2.1.240 are vulnerable to multiple high-severity flaws, including OS command injection and authentication bypass, which could allow remote attackers to achieve full device compromise.","title":"Critical Vulnerabilities in Xiiaozet LK100W","url":"https://feed.craftedsignal.io/briefs/2026-08-xiiaozet-lk100w/"}],"language":"en","title":"CraftedSignal Threat Feed - Xiiaozet","version":"https://jsonfeed.org/version/1.1"}