CVE-2026-78239: Xiiaozet LK100W Missing Authentication for Critical Function
Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. Successful exploitation may permit unauthorized access to the device.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Xiiaozet LK100Wto a version that resolves this vulnerability.Fixed in v2.1.240
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Xiiaozet LK100W devices are exposed where a remote attacker can reach the device's management functionality over the network. The vulnerability requires no privileges or user interaction.
What can an unauthenticated attacker do?
An attacker can invoke a critical management function to enable administrative services that are intended to be restricted. This may lead to unauthorized access to the device and impacts confidentiality, integrity, and availability.