www.cisa.gov 8/27/2026, 4:51:16 PM · external

CISA warns of critical Xiiaozet LK100W flaws, urges patching

CyberSIXT Evidence Panel
Primary Source github.com

THE advisory from CISA (ICSA-26-239-01) dated August 27, 2026, highlights critical vulnerabilities in the Xiiaozet LK100W device. Specific versions (below 2.1.240) are affected, which could allow attackers to exploit these vulnerabilities for unauthorized access and control over the device. Key vulnerabilities identified include OS Command Injection, Missing Authentication for Critical Function, and Authentication Bypass. CISA recommends users upgrade to version 2.1.240 to mitigate these risks.

Users are also advised to follow best practices for cybersecurity, such as minimizing network exposure and employing secure remote access methods. No public exploitation of these vulnerabilities has been reported.

View Primary Source Via www.cisa.gov

Article by CyberSIXT