View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to take control over the device.
The following versions of Xiiaozet LK100W are affected:
LK100W <2.1.240 (CVE-2026-78037, CVE-2026-78239, CVE-2026-76943)
CVSS
Vendor
Equipment
Vulnerabilities
v3 9.8
Xiiaozet
Xiiaozet LK100W
Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’), Missing Authentication for Critical Function, Authentication Bypass Using an Alt…
📰 来源: CISA 安全公告
⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。