CVE-2026-76943: Xiiaozet LK100W Authentication Bypass Using an Alternate Path or Channel
Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Xiiaozet LK100Wto a version that resolves this vulnerability.Fixed in 2.1.240 - Upgrade
Upgrade
Xiiaozet LK100Wtto a version that resolves this vulnerability.Fixed in 2.1.240
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The vulnerability is remotely exploitable over the network and has low attack complexity. It requires no prior privileges and no user interaction.
Which deployments should be considered exposed?
Deployments using Xiiaozet LK100W or Xiiaozet LK100Wt should be assessed, particularly where the administrative service is reachable by untrusted network users.