THE Cybersecurity and Infrastructure Security Agency (CISA) has released an advisory regarding three critical vulnerabilities in the Xiiaozet LK100W device. These vulnerabilities, identified as CVE-2026-78239, CVE-2026-76943, and CVE-2026-78037, have a critical severity rating (CVSS score of 9.8) and can allow remote attackers to bypass authentication and execute arbitrary commands, posing significant risks to device integrity and security.
Users are advised to update to firmware version 2.1.240 to mitigate these risks, as no confirmed exploitation has been reported yet. The vulnerabilities could lead to devices being compromised without user interaction, highlighting the critical nature of the advisory.