Xiiaozet LK100W Multiple Critical Vulnerabilities (OS Command Injection, Missing Authentication, Authentication Bypass)
First seen Aug 28, 2026 · Updated Aug 28, 2026 · CVSS 9.8
The Xiiaozet LK100W device, versions prior to 2.1.240, contains three critical vulnerabilities including OS command injection, missing authentication for a critical function, and an authentication bypass that together could allow a remote attacker to fully compromise the device. Two of the three flaws are rated CVSS v3.1 9.8 (Critical) and require no authentication or user interaction to exploit remotely. CISA has published an advisory recommending immediate firmware update to v2.1.240.
Technical Analysis
CVE-2026-78037 (CVSS 8.8) is an OS command injection (CWE-78) in the web management interface exploitable by an authenticated attacker to run arbitrary OS commands with elevated privileges. CVE-2026-78239 (CVSS 9.8) is a missing authentication for critical function (CWE-306) that lets a remote unauthenticated attacker enable restricted administrative services. CVE-2026-76943 (CVSS 9.8) is an authentication bypass using an alternate path/channel (CWE-288) that can grant unauthorized command execution and privileged access. Chained together, these vulnerabilities enable a fully unauthenticated remote attacker to gain administrative control and execute arbitrary commands on the device, effectively achieving full device takeover. If this device sits on a network used to host or connect to AI agent orchestration systems, RAG pipelines, or automation infrastructure, an attacker gaining device-level command execution could pivot to intercept API keys, model credentials, or agent tool-call traffic traversing the compromised network segment, warranting inclusion in agent-relevant risk assessments.
Affected Systems
Xiiaozet LK100W devices running firmware versions prior to 2.1.240
Indicators of Compromise
- No specific IOCs published; no known public exploitation reported by CISA at this time
Remediation Steps
- 1
Update firmware
Upgrade all Xiiaozet LK100W devices to firmware version 2.1.240 or later as recommended by the vendor.
- 2
Restrict network exposure
Ensure LK100W devices and management interfaces are not accessible from the internet; place them behind firewalls and segment from business/IT networks.
- 3
Enforce secure remote access
If remote administration is required, use an updated, hardened VPN solution rather than direct internet exposure of the device interface.
- 4
Monitor for exploitation
Review logs for unauthorized administrative service activation, unexpected command execution, or anomalous authentication events on affected devices.
- 5
Segment network dependencies
If AI agent or automation infrastructure shares network segments with this device, audit and isolate credential stores and API key usage to limit blast radius from a device compromise.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.