Vulnerability intelligence
CVE-2026-78037
Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise.
CVSS Score
8.8
High
EPSS — Exploit Probability
0.0%
Riskier than 0% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Aug 28, 2026 · latest Aug 28, 2026
Tracked incidents
Coverage timeline
-
CISA Issues Advisory on Xiiaozet LK100W Vulnerabilitiessecurityonline.info · Aug 28, 2026